CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Jasper Project2Fedora JasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack. |
2Fedoraproject Jasper Project2Fedora JasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack. |
3Canonical FedoraprojectGnu3Fedora PatchUbuntu LinuxMay 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a di...Show more |
4Canonical FedoraprojectGnu+1 more4Fedora MageiaPatch+1 moreMay 13, 2026 Aug 25, 2017 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file. |
3Debian FedoraprojectNtp3Debian Linux FedoraNtpMay 13, 2026 Aug 24, 2017 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a de...Show more |
4Debian FedoraprojectRedhat+1 more4Cloudforms Debian LinuxFedora+1 moreMay 13, 2026 Aug 23, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nest...Show more |
2Fedoraproject Vmware2Fedora Spring SocialMay 13, 2026 Aug 22, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3. |
2Cyrusimap Fedoraproject2Cyrus Imap FedoraMay 13, 2026 Aug 22, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command. |
2Entrouvert Fedoraproject2Fedora LassoMay 13, 2026 Aug 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash...Show more |
2Fedoraproject Mit3Fedora KerberosKerberos 5May 13, 2026 Aug 9, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests. |
2Fedoraproject Ganglia2Fedora Ganglia WebMay 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ganglia-web before 3.7.1 allows remote attackers to bypass authentication. |
7Debian FedoraprojectNtp+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 moreMay 13, 2026 Aug 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and...Show more |
4Fedoraproject Jasper ProjectOpensuse+1 more5Fedora JasperLeap+2 moreMay 13, 2026 Aug 2, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file. |
4Fedoraproject Jasper ProjectOpensuse+1 more5Fedora JasperLeap+2 moreMay 13, 2026 Jul 25, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000...Show more |
7Canonical DebianFedoraproject+4 more20Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+17 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more |
10Canonical DebianFedoraproject+7 more18Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+15 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a craft...Show more |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation. |
6Canonical DebianFedoraproject+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+10 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. |
4Canonical FedoraprojectJasper Project+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreMay 13, 2026 Jul 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service. |
4Fedoraproject GolangNovell+1 more4Fedora GoLeap+1 moreMay 13, 2026 Jul 6, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive att...Show more |