CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreMay 6, 2026 Aug 2, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) c...Show more |
3Cronic Project DebianOpensuse4Cronic Debian LinuxLeap+1 moreMay 6, 2026 Jul 26, 2016 N/A· v4 6.2 MEDIUM· v3 4.9 MEDIUM· v2 cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp. |
8Apple CanonicalDebian+5 more14Chrome Debian LinuxEnterprise Linux Desktop+11 moreMay 6, 2026 Jul 23, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to t...Show more |
4Apple DebianFedoraproject+1 more5Debian Linux FedoraIcloud+2 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
4Apple DebianFedoraproject+1 more9Debian Linux FedoraIcloud+6 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
6Canonical DebianIbm+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 6, 2026 Jul 21, 2016 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect...Show more |
5Canonical DebianIbm+2 more6Debian Linux LinuxMariadb+3 moreMay 6, 2026 Jul 21, 2016 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to af...Show more |
5Canonical DebianIbm+2 more6Debian Linux LinuxMariadb+3 moreMay 6, 2026 Jul 21, 2016 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to af...Show more |
5Canonical DebianIbm+2 more6Debian Linux LinuxMariadb+3 moreMay 6, 2026 Jul 21, 2016 N/A· v4 8.1 HIGH· v3 4.1 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidenti...Show more |
8Apache CanonicalDebian+5 more20Communications User Data Repository Debian LinuxEnterprise Linux Desktop+17 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remot...Show more |
8Debian DrupalFedoraproject+5 more13Communications User Data Repository Debian LinuxDrupal+10 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, whi...Show more |
2Debian Redhat2Debian Linux LibvirtMay 6, 2026 Jul 13, 2016 N/A· v4 9.8 CRITICAL· v3 4.3 MEDIUM· v2 libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to...Show more |
3Debian OpenstackRedhat3Debian Linux HorizonOpenstackMay 6, 2026 Jul 12, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS templ...Show more |
2Apache Debian2Debian Linux Xerces C++May 6, 2026 Jul 8, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD. |
3Canonical DebianLibreoffice3Debian Linux LibreofficeUbuntu LinuxMay 6, 2026 Jul 8, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens. |
4Apache CanonicalDebian+1 more6Commons Fileupload Debian LinuxIcewall Identity Manager+3 moreMay 6, 2026 Jul 4, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 Jul 3, 2016 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value,...Show more |
5Canonical DebianLinux+2 more11Debian Linux LinuxLinux Kernel+8 moreMay 6, 2026 Jul 3, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corru...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via...Show more |
4Canonical DebianLinux+1 more4Debian Linux Linux KernelSuse Linux Enterprise Real Time Extension+1 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other i...Show more |