CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectMercurial+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+11 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository. |
6Debian FedoraprojectMercurial+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+11 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository. |
3Debian PythonPython Imaging Project3Debian Linux PillowPython ImagingMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD...Show more |
3Debian FedoraprojectHorde4Debian Linux FedoraGroupware+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web scri...Show more |
4Canonical DebianOpensuse+1 more5Debian Linux LeapOpensuse+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image. |
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled...Show more |
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue. |
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c. |
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command. |
2Debian Xymon2Debian Linux XymonMay 6, 2026 Apr 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, invo...Show more |
2Debian Python2Debian Linux PillowMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file. |
2Debian Python2Debian Linux PillowMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file. |
3Debian FedoraprojectHorde3Debian Linux FedoraGroupwareMay 6, 2026 Apr 13, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5...Show more |
4Canonical DebianNovell+1 more5Debian Linux Suse Linux Enterprise DebuginfoSuse Linux Enterprise Real Time Extension+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 4.4 MEDIUM· v3 1.7 LOW· v2 The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial...Show more |
4Debian LinuxOpensuse+1 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 moreMay 6, 2026 Apr 13, 2016 N/A· v4 6.0 MEDIUM· v3 4.7 MEDIUM· v2 The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer d...Show more |
4Debian OpensuseRedhat+1 more5Debian Linux LeapOpenstack+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of servi...Show more |
2Debian Tryton2Debian Linux TrytondMay 6, 2026 Apr 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields...Show more |
2Debian Roundup Tracker2Debian Linux RoundupMay 6, 2026 Apr 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details. |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Apr 12, 2016 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-d...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation. |