CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Opensc Project2Fedora OpenscApr 23, 2026 May 11, 2009 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of me...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraLinux Enterprise Debuginfo+5 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments. |
7Canonical DebianFedoraproject+4 more9Ctpview Debian LinuxFedora+6 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. |
5Apple CanonicalFedoraproject+2 more9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Apr 9, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or p...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLinux Kernel+2 moreApr 23, 2026 Apr 6, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting...Show more |
8Avaya Christophe.varoquiDebian+5 more11Ctpview Debian LinuxFedora+8 moreApr 23, 2026 Mar 30, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writab...Show more |
2Fedoraproject Redhat5Cluster Project CmanFedora+2 moreApr 23, 2026 Mar 30, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs...Show more |
6Apple DebianFedoraproject+3 more9Debian Linux FedoraIphone Os+6 moreApr 23, 2026 Feb 22, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly e...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraFfmpeg+1 moreApr 23, 2026 Feb 2, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track...Show more |
Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetA...Show more |
3Canonical FedoraprojectPython3Fedora PythonUbuntu LinuxApr 23, 2026 Jan 28, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separat...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux FedoraFirefox+10 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute...Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux FedoraGnutls+4 moreApr 23, 2026 Nov 13, 2008 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows...Show more |
4Canonical DovecotFedoraproject+1 more4Dovecot FedoraOpensuse+1 moreApr 23, 2026 Oct 15, 2008 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions. |
2Bitlbee Fedoraproject2Bitlbee FedoraApr 23, 2026 Sep 11, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NO...Show more |
2Apache Fedoraproject2Fedora OpenofficeApr 23, 2026 Aug 29, 2008 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (appli...Show more |
7Apple CanonicalDebian+4 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreApr 23, 2026 Aug 27, 2008 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafte...Show more |
2Condor Project Fedoraproject2Condor FedoraApr 23, 2026 Jul 31, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypas...Show more |
2Edgewall Fedoraproject2Fedora TracApr 23, 2026 Jul 27, 2008 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the q...Show more |
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields." |