CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Botan Project Fedoraproject2Botan FedoraMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors. |
3Botan Project DebianFedoraproject3Botan Debian LinuxFedoraMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-...Show more |
3Botan Project DebianFedoraproject3Botan Debian LinuxFedoraMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPoppler+1 moreMay 6, 2026 May 6, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrar...Show more |
4Canonical FedoraprojectGnu+1 more4Fedora Libtasn1Opensuse+1 moreMay 6, 2026 May 5, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a c...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraQemu+1 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU cras...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLibgd+3 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which trigge...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range...Show more |
5Canonical FedoraprojectGnu+2 more9Fedora GlibcLinux Enterprise Debuginfo+6 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more |
3Fedoraproject OracleXen3Fedora Vm ServerXenMay 6, 2026 Apr 19, 2016 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping. |
2Fedoraproject Libreswan2Fedora LibreswanMay 6, 2026 Apr 18, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform. |
2Fedoraproject Latex2rtf Project2Fedora Latex2rtfMay 6, 2026 Apr 18, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file...Show more |
2Fedoraproject Fourkitchens2Block Class FedoraMay 6, 2026 Apr 15, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML...Show more |
2Fedoraproject Uninett2Fedora Mod Auth MellonMay 6, 2026 Apr 15, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory con...Show more |
2Fedoraproject Uninett2Fedora Mod Auth MellonMay 6, 2026 Apr 15, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and proc...Show more |
4Debian FedoraprojectLibpng+1 more7Debian Linux Enterprise Linux Desktop SupplementaryEnterprise Linux Hpc Node+4 moreMay 6, 2026 Apr 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote atta...Show more |
4Debian FedoraprojectLibssh2+1 more4Debian Linux FedoraLibssh2+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecif...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attacker...Show more |