CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianMariadb+3 more16Debian Linux Enterprise LinuxEnterprise Linux Desktop+13 moreMay 6, 2026 Jan 21, 2016 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availabi...Show more |
2Debian Oracle2Debian Linux Vm VirtualboxMay 6, 2026 Jan 21, 2016 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and 5.0.14 allows remote attackers to affect availability via unknown vectors related to Core. |
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStora...Show more |
4Canonical DebianIsc+1 more4Debian Linux DhcpUbuntu Linux+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 6.5 MEDIUM· v3 5.7 MEDIUM· v2 ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. |
3Canonical DebianPerl3Debian Linux PathtoolsUbuntu LinuxMay 6, 2026 Jan 13, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protect...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyMay 6, 2026 Jan 12, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyMay 6, 2026 Jan 12, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path. |
6Canonical DebianFedoraproject+3 more11Debian Linux Enterprise Linux EusEnterprise Linux Server+8 moreMay 6, 2026 Jan 12, 2016 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section. |
4Debian OracleQemu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Jan 8, 2016 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large pack...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during cr...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consump...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been gr...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade att...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.2 HIGH· v3 5.0 MEDIUM· v2 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictio...Show more |
4Canonical DebianLinuxfoundation+1 more9Cups Filters Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Dec 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters...Show more |
2Debian Phpmailer Project2Debian Linux PhpmailerMay 6, 2026 Dec 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2...Show more |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, wh...Show more |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive i...Show more |
6Apple CanonicalDebian+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+10 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and...Show more |
7Apple CanonicalDebian+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+12 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors. |