CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 May 20, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds wri...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 May 20, 2016 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (...Show more |
3Debian GnomeOpensuse4Debian Linux LeapLibrsvg+1 moreMay 6, 2026 May 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document. |
2Debian Gnome2Debian Linux LibrsvgMay 6, 2026 May 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document. |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to e...Show more |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based...Show more |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of se...Show more |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and wat...Show more |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to...Show more |
3Apple CanonicalDebian4Debian Linux Iphone OsMac Os X+1 moreMay 6, 2026 May 20, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a crafted XML d...Show more |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbit...Show more |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based...Show more |
5Canonical DebianHp+2 more6Debian Linux Icewall Federation AgentIcewall File Manager+3 moreMay 6, 2026 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux FedoraJboss Middleware+1 moreMay 23, 2025 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow...Show more |
7Canonical DebianHp+4 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and applicatio...Show more |
4Debian OraclePhp+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 6, 2026 May 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, lea...Show more |
6Debian FedoraprojectMariadb+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 May 16, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof server...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 May 14, 2016 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requ...Show more |
5Canonical DebianGoogle+2 more6Chrome Debian LinuxNode.js+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to caus...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to...Show more |