CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Feb 16, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash)...Show more |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Feb 16, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-base...Show more |
2Debian Linux2Debian Linux Linux KernelApr 29, 2026 Feb 15, 2010 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess." |
2Debian Linux2Debian Linux Linux KernelApr 29, 2026 Feb 12, 2010 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (...Show more |
2Canonical Debian3Debian Linux LintianUbuntu LinuxApr 29, 2026 Feb 2, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vector...Show more |
2Debian Linux2Debian Linux Linux KernelApr 29, 2026 Jan 26, 2010 N/A· v4 N/A· v3 5.4 MEDIUM· v2 The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations...Show more |
2Debian Linux2Debian Linux Linux KernelApr 23, 2026 Jan 12, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified i...Show more |
2Debian Linux2Debian Linux Linux KernelApr 23, 2026 Jan 12, 2010 N/A· v4 N/A· v3 7.8 HIGH· v2 drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service...Show more |
2Debian Linux2Debian Linux Linux KernelApr 23, 2026 Jan 12, 2010 N/A· v4 N/A· v3 7.8 HIGH· v2 drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which al...Show more |
3Debian OpensuseTransmissionbt3Debian Linux OpensuseTransmissionApr 23, 2026 Jan 8, 2010 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file. |
5Canonical DebianMariadb+2 more5Debian Linux MariadbMysql+2 moreApr 23, 2026 Dec 30, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through...Show more |
3Apple DebianPhp3Debian Linux Mac Os XPhpApr 23, 2026 Nov 24, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exha...Show more |
7Canonical DebianLinux+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 23, 2026 Nov 20, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an...Show more |
5Apple CanonicalDebian+2 more7Cups Debian LinuxEnterprise Linux+4 moreApr 23, 2026 Nov 20, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a de...Show more |
7Avaya CanonicalDebian+4 more18Aura Application Enablement Services Aura Communication ManagerAura Session Manager+15 moreApr 23, 2026 Nov 16, 2009 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. |
8Apache CanonicalDebian+5 more8Debian Linux FedoraGnutls+5 moreMay 27, 2026 Nov 9, 2009 N/A· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and...Show more |
3Debian F5Fedoraproject3Debian Linux FedoraNginxApr 23, 2026 Sep 15, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests. |
2Debian Prototypejs2Debian Linux PrototypeApr 23, 2026 Sep 13, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. |
6Apache AppleDebian+3 more7Debian Linux FedoraHttp Server+4 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraHttp ServerApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 2.6 LOW· v2 The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and...Show more |