← Back

Linux

linux

Vendor: Oracle • 229 CVEs

CVEs (229)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
4Jdk
JreJrockit+1 more
May 6, 2026
Jul 21, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than C...Show more
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3500.Show less
1Oracle
4Jdk
JreJrockit+1 more
May 6, 2026
Jul 21, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than C...Show more
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3508.Show less
5Canonical
DebianIbm+2 more
6Debian Linux
LinuxMariadb+3 more
May 6, 2026
Jul 21, 2016
N/A· v4
8.1 HIGH· v3
4.1 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidenti...Show more
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.Show less
1Oracle
3Jdk
JreLinux
May 6, 2026
Jul 21, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors related to CORBA.
4Ibm
MariadbOracle+1 more
5Enterprise Linux
LinuxMariadb+2 more
May 6, 2026
Jul 21, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confi...Show more
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Security: Encryption.Show less
4Apache
HpOracle+1 more
11Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+8 more
May 6, 2026
Jul 19, 2016
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_...Show more
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.Show less
8Apache
CanonicalDebian+5 more
20Communications User Data Repository
Debian LinuxEnterprise Linux Desktop+17 more
May 6, 2026
Jul 19, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remot...Show more
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.Show less
4Fedoraproject
GolangOracle+1 more
6Enterprise Linux Server
Enterprise Linux Server AusEnterprise Linux Server Eus+3 more
May 6, 2026
Jul 19, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY...Show more
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.Show less
8Debian
DrupalFedoraproject+5 more
13Communications User Data Repository
Debian LinuxDrupal+10 more
May 6, 2026
Jul 19, 2016
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, whi...Show more
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.Show less
3Canonical
LinuxOracle
3Linux
Linux KernelUbuntu Linux
May 6, 2026
Jul 3, 2016
N/A· v4
7.1 HIGH· v3
5.6 MEDIUM· v2
The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information fro...Show more
The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary.Show less
5Canonical
DebianLinux+2 more
11Debian Linux
LinuxLinux Kernel+8 more
May 6, 2026
Jul 3, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corru...Show more
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.Show less
4Linux
NovellOracle+1 more
14Enterprise Linux
Enterprise Linux DesktopEnterprise Linux For Real Time+11 more
May 6, 2026
Jun 27, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash)...Show more
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.Show less
6Canonical
DebianNodejs+3 more
7Debian Linux
LinuxLinux Enterprise+4 more
May 6, 2026
Jun 20, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.Show less
3Hp
OpensslOracle
6Icewall Mcrp
Icewall SsoIcewall Sso Agent Option+3 more
May 6, 2026
Jun 20, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspec...Show more
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.Show less
7Canonical
DebianGraphicsmagick+4 more
14Debian Linux
GraphicsmagickImagemagick+11 more
May 6, 2026
Jun 10, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
8Apple
HpMcafee+5 more
19Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+16 more
May 6, 2026
Jun 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
5Canonical
DebianOracle+2 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+9 more
May 6, 2026
Jun 1, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asy...Show more
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.Show less
3Canonical
LinuxOracle
3Linux
Linux KernelUbuntu Linux
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or p...Show more
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation.Show less
4Canonical
LinuxNovell+1 more
6Linux
Linux KernelSuse Linux Enterprise Debuginfo+3 more
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from...Show more
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.Show less
5Canonical
LinuxNovell+2 more
12Enterprise Linux
LinuxLinux Kernel+9 more
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecifie...Show more
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.Show less