CVEs (1,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical Dosfstools ProjectOpensuse4Dosfstools LeapOpensuse+1 moreMay 6, 2026 Jun 3, 2016 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out...Show more |
3Canonical Dosfstools ProjectOpensuse4Dosfstools LeapOpensuse+1 moreMay 6, 2026 Jun 3, 2016 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to...Show more |
3Fedoraproject GnuOpensuse4Fedora GlibcLeap+1 moreMay 6, 2026 Jun 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name. |
9Apple CanonicalDebian+6 more14Debian Linux FirefoxLeap+11 moreMay 6, 2026 May 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. |
2Opensuse Quagga3Leap OpensuseQuaggaMay 6, 2026 May 23, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a la...Show more |
3Fedoraproject GolangOpensuse3Fedora GoLeapMay 6, 2026 May 23, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (in...Show more |
5Canonical DebianLinux+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 May 23, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer inter...Show more |
4Debian FedoraprojectOpensuse+1 more5Debian Linux FedoraLeap+2 moreMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out...Show more |
4Fedoraproject HpOpensuse+1 more4Fedora LeapPhp+1 moreMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bou...Show more |
3Fedoraproject OpensusePhp3Fedora LeapPhpMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of serv...Show more |
3Fedoraproject OpensusePhp3Fedora LeapPhpMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly ha...Show more |
3Fedoraproject OpensusePhp3Fedora LeapPhpMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...Show more |
3Fedoraproject OpensusePhp3Fedora LeapPhpMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possi...Show more |
3Fedoraproject OpensusePhp3Fedora LeapPhpMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ glo...Show more |
3Fedoraproject OpensusePhp3Fedora LeapPhpMay 6, 2026 May 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service o...Show more |
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-ba...Show more |
ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or poss...Show more |
4Canonical OpensusePhp+1 more6Leap Linux Enterprise Module For Web ScriptingLinux Enterprise Software Development Kit+3 moreMay 6, 2026 May 22, 2016 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML...Show more |
3Debian GnomeOpensuse4Debian Linux LeapLibrsvg+1 moreMay 6, 2026 May 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document. |
5Canonical DebianHp+2 more6Debian Linux Icewall Federation AgentIcewall File Manager+3 moreMay 6, 2026 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service...Show more |