CVEs (1,059)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. |
3Libarchive OracleRedhat10Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 moreMay 6, 2026 Sep 21, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file. |
3Libarchive OracleRedhat10Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file. |
3Libarchive OracleRedhat9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large...Show more |
2Libarchive Redhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary. |
2Libarchive Redhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, w...Show more |
5Debian MariadbOracle+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreMay 6, 2026 Sep 20, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5...Show more |
5Canonical DebianOracle+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Server+10 moreMay 6, 2026 Aug 2, 2016 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion...Show more |
4Ibm MariadbOracle+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 Jul 21, 2016 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confi...Show more |
6Canonical DebianIbm+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 6, 2026 Jul 21, 2016 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect...Show more |
4Fedoraproject HpIsc+1 more9Bind Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Jul 19, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request...Show more |
4Apache HpOracle+1 more11Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+8 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_...Show more |
8Apache CanonicalDebian+5 more20Communications User Data Repository Debian LinuxEnterprise Linux Desktop+17 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remot...Show more |
4Fedoraproject GolangOracle+1 more6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY...Show more |
4Linux NovellOracle+1 more14Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Real Time+11 moreMay 6, 2026 Jun 27, 2016 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash)...Show more |
3Canonical LinuxRedhat9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data. |
4Canonical DebianLibndp+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+7 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of s...Show more |
6Canonical DebianMozilla+3 more21Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+18 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
8Apple HpMcafee+5 more19Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+16 moreMay 6, 2026 Jun 9, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. |
4Debian OpensuseRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreMay 6, 2026 Jun 9, 2016 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261. |