CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianOpenssl3Debian Linux OpensslUbuntu LinuxApr 23, 2026 May 13, 2008 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guess...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreApr 23, 2026 May 7, 2008 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which...Show more |
4Canonical DebianMysql+1 more4Debian Linux MysqlMysql+1 moreApr 23, 2026 May 5, 2008 N/A· v4 N/A· v3 4.6 MEDIUM· v2 MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreApr 23, 2026 May 2, 2008 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 18, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 10, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffe...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreApr 23, 2026 Mar 31, 2008 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information. |
2Debian Lighttpd2Debian Linux LighttpdApr 23, 2026 Mar 27, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error,...Show more |
7Apple CanonicalDebian+4 more11Debian Linux FedoraKerberos 5+8 moreApr 23, 2026 Mar 19, 2008 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraKerberos 5+1 moreApr 23, 2026 Mar 19, 2008 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that...Show more |
4Apple CanonicalDebian+1 more4Debian Linux Mac Os XUbuntu Linux+1 moreMay 1, 2025 Mar 17, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via u...Show more |
scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options. |
7Apple CanonicalDebian+4 more11Debian Linux FedoraLinux+8 moreApr 23, 2026 Jan 18, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerabili...Show more |
3Debian MandrakesoftRedhat4Debian Linux FedoraMandrake Linux+1 moreApr 23, 2026 Jan 12, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences. |
6Apple CanonicalDebian+3 more6Debian Linux Mac Os XMysql+3 moreApr 23, 2026 Jan 10, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "inp...Show more |
3Debian FedoraprojectPostgresql3Debian Linux FedoraPostgresqlApr 23, 2026 Jan 9, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileg...Show more |
4Canonical DebianPostgresql+1 more4Debian Linux PostgresqlTcl/tk+1 moreApr 23, 2026 Jan 9, 2008 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (in...Show more |
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxApr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow. |
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments. |