CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject RedhatSelinux Project7Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+4 moreMay 13, 2026 Jan 19, 2017 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. |
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables. |
4Debian FedoraprojectGstreamer+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 13, 2026 Jan 13, 2017 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibbsd+1 moreMay 13, 2026 Jan 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow. |
2Fedoraproject Jenkins2Fedora JenkinsMay 13, 2026 Jan 12, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server. |
2Fedoraproject Igniterealtime2Fedora SmackMay 6, 2026 Jan 12, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client auth...Show more |
2Fedoraproject Gnu2Fedora GuileMay 6, 2026 Jan 12, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack. |
2Fedoraproject Gnu2Fedora GuileMay 6, 2026 Jan 12, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example,...Show more |
4Debian FedoraprojectKde+1 more4Debian Linux FedoraKmail+1 moreMay 6, 2026 Dec 23, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space int...Show more |
3Fedoraproject KdeOpensuse4Fedora KscreenlockerLeap+1 moreMay 6, 2026 Dec 23, 2016 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again. |
37 Zip FedoraprojectOracle37 Zip FedoraSolarisMay 6, 2026 Dec 13, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image. |
2Fedoraproject X.org2Fedora LibxvmcMay 6, 2026 Dec 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string. |
2Fedoraproject X.org2Fedora LibxtstMay 6, 2026 Dec 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence...Show more |
2Fedoraproject X2Fedora LibxtstMay 6, 2026 Dec 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks. |
2Fedoraproject X.org2Fedora LibxrenderMay 6, 2026 Dec 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths. |
2Fedoraproject X.org2Fedora LibxrenderMay 6, 2026 Dec 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fiel...Show more |
2Fedoraproject X.org2Fedora LibxrandrMay 6, 2026 Dec 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data. |
2Fedoraproject X.org2Fedora LibxrandrMay 6, 2026 Dec 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response. |
2Fedoraproject X.org2Fedora LibxiMay 6, 2026 Dec 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields. |
2Fedoraproject X.org2Fedora LibxiMay 6, 2026 Dec 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields. |