CVEs (1,928)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apple DebianGoogle+1 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreApr 29, 2026 Aug 29, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression. |
2Linux Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreApr 29, 2026 Jul 28, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service...Show more |
2Linux Redhat6Enterprise Linux Aus Enterprise Linux DesktopEnterprise Linux Eus+3 moreApr 29, 2026 Jul 28, 2011 N/A· v4 N/A· v3 1.9 LOW· v2 The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getso...Show more |
2Linux Redhat6Enterprise Linux Aus Enterprise Linux DesktopEnterprise Linux Eus+3 moreApr 29, 2026 Jul 18, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which al...Show more |
2Linux Redhat7Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+4 moreApr 29, 2026 May 9, 2011 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of servi...Show more |
2Linux Redhat7Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+4 moreApr 29, 2026 May 9, 2011 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and cons...Show more |
2Linux Redhat7Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+4 moreApr 29, 2026 May 9, 2011 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted...Show more |
3Canonical LinuxRedhat8Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+5 moreApr 29, 2026 May 3, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system ca...Show more |
3Linux RedhatSuse7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Apr 10, 2011 N/A· v4 N/A· v3 2.1 LOW· v2 The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from...Show more |
3Linux RedhatSuse6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 29, 2026 Apr 4, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted applica...Show more |
3Canonical LinuxRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Mar 15, 2011 N/A· v4 N/A· v3 5.7 MEDIUM· v2 Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request...Show more |
2Linux Redhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+3 moreApr 29, 2026 Mar 1, 2011 N/A· v4 N/A· v3 2.1 LOW· v2 The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kern...Show more |
2Linux Redhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Feb 18, 2011 N/A· v4 N/A· v3 2.1 LOW· v2 The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information...Show more |
2Linux Redhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Feb 18, 2011 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecifie...Show more |
10Apache AppleDebian+7 more17Chrome Debian LinuxEnterprise Linux Desktop+14 moreApr 29, 2026 Dec 7, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impac...Show more |
9Apache AppleCanonical+6 more15Chrome Debian LinuxEnterprise Linux Desktop+12 moreApr 29, 2026 Nov 17, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows con...Show more |
3Google RedhatWebmproject5Chrome Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 29, 2026 Nov 6, 2010 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames...Show more |
9Apple CanonicalDebian+6 more11Cups Debian LinuxEnterprise Linux Desktop+8 moreApr 29, 2026 Nov 5, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a deni...Show more |
7Apple CanonicalDebian+4 more13Cups Debian LinuxEnterprise Linux+10 moreApr 29, 2026 Nov 5, 2010 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application c...Show more |
4Apple FedoraprojectRedhat+1 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreApr 29, 2026 Jun 22, 2010 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number. |