CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianGoogle4Chrome Chrome OsDebian Linux+1 moreApr 29, 2026 Jan 14, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corrupt...Show more |
2Debian Google3Chrome Chrome OsDebian LinuxApr 29, 2026 Jan 14, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of servic...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service (system crash) via malformed X.25 (1) X...Show more |
The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by r...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 1.9 LOW· v2 net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by levera...Show more |
The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory...Show more |
4Debian LinuxOpensuse+1 more4Debian Linux Linux Enterprise ServerLinux Kernel+1 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified o...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a s...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large n...Show more |
5Debian FedoraprojectLinux+2 more7Debian Linux FedoraLinux Enterprise Desktop+4 moreApr 29, 2026 Dec 29, 2010 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow...Show more |
2Debian Linux2Debian Linux Linux KernelApr 29, 2026 Dec 29, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the...Show more |
2Debian Google3Chrome Chrome OsDebian LinuxApr 29, 2026 Dec 22, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown...Show more |
4Debian FedoraprojectGoogle+1 more5Chrome Chrome OsDebian Linux+2 moreApr 29, 2026 Dec 22, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly par...Show more |
4Canonical DebianExim+1 more4Debian Linux EximOpensuse+1 moreApr 21, 2026 Dec 14, 2010 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated...Show more |
4Canonical DebianExim+1 more4Debian Linux EximOpensuse+1 moreApr 21, 2026 Dec 14, 2010 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large...Show more |
2Debian Linux2Debian Linux Linux KernelApr 29, 2026 Dec 10, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instr...Show more |
10Apache AppleDebian+7 more17Chrome Debian LinuxEnterprise Linux Desktop+14 moreApr 29, 2026 Dec 7, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impac...Show more |
Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events. |
Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations. |