CVEs (1,928)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache CanonicalRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 23, 2026 Mar 30, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resourc...Show more |
5Canonical NovellPhp+2 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreApr 23, 2026 Mar 6, 2007 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable...Show more |
2Ekiga Redhat3Ekiga Enterprise LinuxEnterprise Linux DesktopApr 23, 2026 Feb 20, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled...Show more |
2Linux Redhat3Enterprise Linux Enterprise Linux DesktopLinux KernelApr 23, 2026 Jan 30, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors. |
5Canonical FedoraprojectGd Graphics Library Project+2 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreApr 23, 2026 Jan 30, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...Show more |
6Gnu Gpg4winRedhat+3 more9Enterprise Linux Enterprise Linux DesktopFedora Core+6 moreApr 23, 2026 Dec 7, 2006 N/A· v4 N/A· v3 10.0 HIGH· v2 A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a funct...Show more |
3Debian FedoraprojectRedhat8Debian Linux Enterprise LinuxEnterprise Linux Desktop+5 moreApr 23, 2026 Oct 10, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse cont...Show more |
3Canonical LinuxRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 23, 2026 Oct 5, 2006 N/A· v4 7.5 HIGH· v3 3.3 LOW· v2 The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a...Show more |
2Kde Redhat3Enterprise Linux Enterprise Linux DesktopKdeApr 16, 2026 Jul 27, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop. |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null derefer...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated usi...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDe...Show more |
2Gnu Redhat4Enterprise Linux Enterprise Linux DesktopLinux Advanced Workstation+1 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 2.6 LOW· v2 The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files v...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Dec 22, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords. |
4Apache CanonicalFedoraproject+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 16, 2026 Oct 25, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transa...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Oct 25, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash). |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Sep 1, 2005 N/A· v4 N/A· v3 7.2 HIGH· v2 init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) a...Show more |
3Apache DebianRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 16, 2026 Aug 5, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that c...Show more |
1Redhat 4Enterprise Linux Enterprise Linux DesktopLinux Advanced Workstation+1 moreApr 16, 2026 Jun 13, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 May 18, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain action...Show more |