CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickOpensuse+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image....Show more |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickOpensuse+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via...Show more |
2Debian Dropbear Ssh Project2Debian Linux Dropbear SshApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 7.1 HIGH· v2 Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command...Show more |
5Canonical DebianImagemagick+2 more11Debian Linux Enterprise Linux AusEnterprise Linux Desktop+8 moreApr 29, 2026 Jun 5, 2012 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickOpensuse+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG fi...Show more |
4Canonical DebianImagemagick+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 Jun 5, 2012 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF. |
4Canonical DebianImagemagick+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 Jun 5, 2012 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxApr 29, 2026 Jun 2, 2012 N/A· v4 N/A· v3 2.6 LOW· v2 chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows r...Show more |
4Canonical DebianFedoraproject+1 more5Debian Linux FedoraPuppet+2 moreApr 29, 2026 May 29, 2012 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on t...Show more |
4Canonical DebianLinux+1 more6Debian Linux Linux Enterprise DesktopLinux Enterprise High Availability Extension+3 moreApr 29, 2026 May 17, 2012 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple proce...Show more |
8Apple DebianFedoraproject+5 more17Application Stack Debian LinuxEnterprise Linux Desktop+14 moreApr 21, 2026 May 11, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers...Show more |
The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under th...Show more |
3Debian F5Fedoraproject3Debian Linux FedoraNginxApr 29, 2026 Apr 17, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client requ...Show more |
6Debian FedoraprojectGoogle+3 more13Chrome Debian LinuxEnterprise Linux+10 moreApr 29, 2026 Mar 22, 2012 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (appl...Show more |
4Debian MozillaOpensuse+1 more8Debian Linux FirefoxLinux Enterprise Desktop+5 moreApr 29, 2026 Feb 1, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
5Canonical DebianMozilla+2 more9Debian Linux FirefoxLinux Enterprise Desktop+6 moreApr 29, 2026 Feb 1, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a...Show more |
4Debian MozillaOpensuse+1 more8Debian Linux FirefoxLinux Enterprise Desktop+5 moreApr 29, 2026 Feb 1, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a d...Show more |
5Apache DebianOpensuse+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreApr 29, 2026 Jan 28, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of...Show more |
5Apache DebianOpensuse+2 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreApr 29, 2026 Jan 18, 2012 N/A· v4 N/A· v3 4.6 MEDIUM· v2 scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field wi...Show more |
2Debian Mediawiki2Debian Linux MediawikiApr 29, 2026 Jan 8, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning fun...Show more |