CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay...Show more |
2Debian Roaring Penguin2Debian Linux PppoeApr 16, 2026 Dec 23, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a...Show more |
7Altlinux ConectivaDebian+4 more9Alt Linux Debian LinuxEnterprise Linux+6 moreApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows...Show more |
7Altlinux ConectivaDebian+4 more9Alt Linux Debian LinuxEnterprise Linux+6 moreApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet. |
7Altlinux ConectivaDebian+4 more9Alt Linux Debian LinuxEnterprise Linux+6 moreApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash). |
3Debian GentooPavuk3Debian Linux LinuxPavukApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 7.6 HIGH· v2 Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header. |
2Debian Www Sql Project2Debian Linux Www SqlApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql. |
Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in message...Show more |
2Debian Mailreader.com2Debian Linux Mailreader.comApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter. |
3Debian MysqlOracle3Debian Linux MysqlMysqlApr 16, 2026 Nov 3, 2004 N/A· v4 N/A· v3 2.6 LOW· v2 MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs. |
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a...Show more |
3Debian MysqlOracle3Debian Linux MysqlMysqlApr 16, 2026 Nov 3, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could all...Show more |
3Debian MitOpenpkg3Debian Linux Kerberos 5OpenpkgApr 16, 2026 Oct 20, 2004 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code. |
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files. |
3Debian MitRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 16, 2026 Sep 28, 2004 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code. |
3Debian MitRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 16, 2026 Sep 28, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to...Show more |
2Debian Nicolas Boullis2Debian Linux Mah JongApr 16, 2026 Sep 28, 2004 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference. |
8Apache DebianGentoo+5 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreApr 16, 2026 Sep 16, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access. |
3Debian UserminWebmin3Debian Linux UserminWebminApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords. |
2Debian William Deich2Debian Linux SuperApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 7.2 HIGH· v2 Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root. |