CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifie...Show more |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors. |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via cr...Show more |
4Debian GoogleOpensuse+1 more4Chrome Debian LinuxLeap+1 moreMay 6, 2026 Apr 18, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to...Show more |
4Debian GoogleOpensuse+1 more4Chrome Debian LinuxLeap+1 moreMay 6, 2026 Apr 18, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive i...Show more |
3Canonical DebianLinuxfoundation4Cups Filters Debian LinuxFoomatic Filters+1 moreMay 6, 2026 Apr 14, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) charact...Show more |
4Debian FedoraprojectLibpng+1 more7Debian Linux Enterprise Linux Desktop SupplementaryEnterprise Linux Hpc Node+4 moreMay 6, 2026 Apr 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote atta...Show more |
2Apache Debian2Debian Linux SubversionMay 6, 2026 Apr 14, 2016 N/A· v4 7.6 HIGH· v3 8.0 HIGH· v2 Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumpt...Show more |
4Debian FedoraprojectLibssh2+1 more4Debian Linux FedoraLibssh2+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecif...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attacker...Show more |
3Canonical DebianXmlsoft3Debian Linux Libxml2Ubuntu LinuxMay 6, 2026 Apr 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML do...Show more |
2Debian Libtiff2Debian Linux LibtiffMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif. |
2Debian Libtiff2Debian Linux LibtiffMay 6, 2026 Apr 13, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibssh+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer derefere...Show more |
2Debian Libtiff2Debian Linux LibtiffMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif. |
2Debian Remotesensing2Debian Linux LibtiffMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image,...Show more |
4Canonical DebianOpensuse+1 more5Debian Linux LeapOpensuse+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code...Show more |
3Canonical DebianOptipng Project3Debian Linux OptipngUbuntu LinuxMay 6, 2026 Apr 13, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbit...Show more |
5Debian FedoraprojectMercurial+2 more7Debian Linux FedoraLeap+4 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records. |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraVm Server+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content i...Show more |