CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraFontconfig+1 moreMay 6, 2026 Aug 13, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file. |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraLeap+3 moreMay 6, 2026 Aug 10, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors. |
2Fedoraproject Microsoft5Fedora Windows 10Windows 8.1+2 moreMay 6, 2026 Aug 9, 2016 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access...Show more |
2Fedoraproject Openbsd2Fedora OpensshMay 6, 2026 Aug 7, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) vi...Show more |
5Debian FedoraprojectFreebsd+2 more6Debian Linux Enterprise LinuxFedora+3 moreMay 6, 2026 Aug 7, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraPerl+2 moreMay 6, 2026 Aug 2, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working...Show more |
5Apache DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreMay 6, 2026 Aug 2, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) c...Show more |
4Apple DebianFedoraproject+1 more5Debian Linux FedoraIcloud+2 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
4Apple DebianFedoraproject+1 more9Debian Linux FedoraIcloud+6 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
3Apple FedoraprojectXmlsoft4Fedora IcloudItunes+1 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
3Apple FedoraprojectXmlsoft8Fedora IcloudIphone Os+5 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
4Fedoraproject HpIsc+1 more9Bind Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Jul 19, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request...Show more |
8Apache CanonicalDebian+5 more20Communications User Data Repository Debian LinuxEnterprise Linux Desktop+17 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remot...Show more |
4Fedoraproject GolangOracle+1 more6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY...Show more |
8Debian DrupalFedoraproject+5 more13Communications User Data Repository Debian LinuxDrupal+10 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, whi...Show more |
3Fedoraproject GraphicsmagickSuse5Fedora GraphicsmagickLinux Enterprise Debuginfo+2 moreMay 6, 2026 Jul 13, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file. |
3Fedoraproject Pivotal SoftwareVmware3Fedora Spring FrameworkSpring FrameworkMay 6, 2026 Jul 12, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumptio...Show more |
4Fedoraproject LinuxRedhat+1 more11Enterprise Linux FedoraLinux Enterprise Debuginfo+8 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by...Show more |
3Fedoraproject OpensuseQuassel Irc4Fedora LeapOpensuse+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data. |
3Fedoraproject OcamlOpensuse3Fedora OcamlOpensuseMay 6, 2026 Jun 13, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function. |