CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vec...Show more |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and Loca...Show more |
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings...Show more |
5Canonical DebianOracle+2 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Jun 1, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asy...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Jun 1, 2016 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO reg...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Jun 1, 2016 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command. |
2Debian Sensiolabs2Debian Linux SymfonyMay 6, 2026 Jun 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not lim...Show more |
2Debian Sensiolabs2Debian Linux SymfonyMay 6, 2026 Jun 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat...Show more |
2Debian Gnome2Debian Linux Gdk PixbufMay 6, 2026 Jun 1, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial...Show more |
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF. |
9Apple CanonicalDebian+6 more14Debian Linux FirefoxLeap+11 moreMay 6, 2026 May 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. |
4Canonical DebianQemu+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreMay 6, 2026 May 25, 2016 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraQemu+1 moreMay 6, 2026 May 23, 2016 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siT...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraQemu+1 moreMay 6, 2026 May 23, 2016 N/A· v4 8.6 HIGH· v3 4.3 MEDIUM· v2 Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cause a denial of servic...Show more |
The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular isochronous transfer descriptor (iTD) list. |
5Canonical DebianLinux+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 May 23, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer inter...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 May 23, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecifi...Show more |
4Debian FedoraprojectOpensuse+1 more5Debian Linux FedoraLeap+2 moreMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out...Show more |