CVEs (1,454)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical FedoraprojectOpensuse+2 more5Fedora Linux Enterprise ServerOpensuse+2 moreApr 29, 2026 May 27, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a...Show more |
7Canonical DebianFedoraproject+4 more7Database Server Debian LinuxFedora+4 moreApr 29, 2026 May 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for inva...Show more |
3Opensuse PhpSuse3Linux Enterprise OpensusePhpApr 29, 2026 May 7, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative ch...Show more |
4Debian LinuxOpensuse+1 more6Debian Linux Linux Enterprise DesktopLinux Enterprise High Availability Extension+3 moreApr 29, 2026 May 7, 2010 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly h...Show more |
5Canonical FedoraprojectMit+2 more5Fedora Kerberos 5Linux Enterprise+2 moreApr 29, 2026 Apr 7, 2010 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a ka...Show more |
3Canonical OpensuseOracle3Jre OpensuseUbuntu LinuxApr 21, 2026 Apr 1, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail...Show more |
4Apple CanonicalFedoraproject+1 more5Fedora Iphone OsOpensuse+2 moreApr 29, 2026 Mar 15, 2010 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags. |
7Apple CanonicalDebian+4 more7Debian Linux FedoraLibpng+4 moreApr 29, 2026 Mar 3, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large unco...Show more |
openSUSE 11.2 installs the devtmpfs root directory with insecure permissions (1777), which allows local users to gain privileges via unspecified vectors. |
3Canonical LinuxOpensuse3Linux Kernel OpensuseUbuntu LinuxApr 29, 2026 Feb 15, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an...Show more |
3Adobe OpensuseSuse4Acrobat Linux EnterpriseLinux Enterprise Debuginfo+1 moreApr 21, 2026 Jan 13, 2010 N/A· v4 8.8 HIGH· v3 10.0 HIGH· v2 The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document,...Show more |
6Adium FedoraprojectOpensuse+3 more7Adium Enterprise LinuxFedora+4 moreApr 23, 2026 Jan 9, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emo...Show more |
3Debian OpensuseTransmissionbt3Debian Linux OpensuseTransmissionApr 23, 2026 Jan 8, 2010 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file. |
3Adobe OpensuseSuse5Acrobat Acrobat ReaderLinux Enterprise+2 moreApr 21, 2026 Dec 15, 2009 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code v...Show more |
7Canonical DebianLinux+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 23, 2026 Nov 20, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an...Show more |
7Avaya CanonicalDebian+4 more18Aura Application Enablement Services Aura Communication ManagerAura Session Manager+15 moreApr 23, 2026 Nov 16, 2009 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. |
4Apple FedoraprojectGoogle+1 more5Chrome FedoraIphone Os+2 moreApr 23, 2026 Nov 13, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-ori...Show more |
8Canonical FedoraprojectLinux+5 more14Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+11 moreApr 23, 2026 Nov 4, 2009 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous...Show more |
iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unsp...Show more |
6Canonical FedoraprojectLinux+3 more8Esx FedoraLinux Kernel+5 moreApr 23, 2026 Oct 22, 2009 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on thi...Show more |