CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits us...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 6.4 MEDIUM· v3 8.5 HIGH· v2 The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded conten...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 7.4 HIGH· v3 6.4 MEDIUM· v2 Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a doub...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting atta...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulat...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method. |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.5 MEDIUM· v2 The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveragin...Show more |
2Debian Inspircd2Debian Linux InspircdMay 6, 2026 Apr 12, 2016 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) char...Show more |
2Debian Redmine2Debian Linux RedmineMay 6, 2026 Apr 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed. |
2Debian Redmine2Debian Linux RedmineMay 6, 2026 Apr 12, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arb...Show more |
2Debian Redmine2Debian Linux RedmineMay 6, 2026 Apr 12, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with rela...Show more |
2Debian Redmine2Debian Linux RedmineMay 6, 2026 Apr 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form. |
4Canonical DebianQemu+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreMay 6, 2026 Apr 12, 2016 N/A· v4 8.4 HIGH· v3 3.6 LOW· v2 The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet. |
3Debian QemuRedhat4Debian Linux OpenstackQemu+1 moreMay 6, 2026 Apr 12, 2016 N/A· v4 8.8 HIGH· v3 6.9 MEDIUM· v2 Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHC...Show more |
2Debian Xmlsoft2Debian Linux Libxml2May 6, 2026 Apr 11, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified...Show more |
2Debian Kamailio2Debian Linux KamailioMay 6, 2026 Apr 11, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and pro...Show more |
2Debian Oar Project2Debian Linux OarMay 6, 2026 Apr 11, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options. |
2Debian Dhcpcd Project2Debian Linux DhcpcdMay 6, 2026 Apr 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response. |
2Debian Dhcpcd Project2Debian Linux DhcpcdMay 6, 2026 Apr 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response. |