CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibssh+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer derefere...Show more |
5Debian FedoraprojectMercurial+2 more7Debian Linux FedoraLeap+4 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records. |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraVm Server+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content i...Show more |
3Fedoraproject OracleXen3Fedora Vm ServerXenMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content info...Show more |
6Debian FedoraprojectMercurial+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+11 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository. |
6Debian FedoraprojectMercurial+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+11 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository. |
3Debian FedoraprojectHorde4Debian Linux FedoraGroupware+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web scri...Show more |
3Debian FedoraprojectHorde3Debian Linux FedoraGroupwareMay 6, 2026 Apr 13, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5...Show more |
2Fedoraproject Giflib Project2Fedora GiflibMay 6, 2026 Apr 13, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file. |
2Apache Fedoraproject2Fedora Qpid ProtonMay 6, 2026 Apr 12, 2016 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SS...Show more |
2Fedoraproject Nodejs2Fedora Node.jsMay 6, 2026 Apr 7, 2016 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection...Show more |
2Fedoraproject Nodejs2Fedora Node.jsMay 6, 2026 Apr 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header. |
2Fedoraproject Samsung2Fedora X14j FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segment...Show more |
3Fedoraproject OpensuseProftpd3Fedora OpensuseProftpdMay 6, 2026 Apr 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently al...Show more |
3Debian FedoraprojectFuseiso Project3Debian Linux FedoraFuseisoMay 6, 2026 Mar 30, 2016 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathnam...Show more |
2Fedoraproject Fuseiso Project2Fedora FuseisoMay 6, 2026 Mar 30, 2016 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF bl...Show more |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db....Show more |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure an...Show more |
2Digium Fedoraproject3Asterisk Certified AsteriskFedoraMay 6, 2026 Feb 22, 2016 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3, when the timert1 sip.conf configuration is set...Show more |
2Fedoraproject Moodle2Fedora MoodleMay 6, 2026 Feb 22, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to in...Show more |