CVEs (768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Aug 31, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls. |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Aug 31, 2017 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem. |
3Debian RedhatRubygems8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Aug 31, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command. |
3Debian RedhatRubygems8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Aug 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences. |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Aug 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encou...Show more |
3Debian Icoutils ProjectRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Aug 22, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash)...Show more |
6Apache CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 13, 2026 Aug 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the...Show more |
6Apache CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 13, 2026 Aug 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to thos...Show more |
6Apache CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 13, 2026 Aug 10, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 t...Show more |
6Apache CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 13, 2026 Aug 10, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that...Show more |
6Apache CanonicalDebian+3 more15Communications Diameter Signaling Router Debian LinuxEnterprise Linux Desktop+12 moreMay 13, 2026 Aug 10, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not e...Show more |
4Debian MariadbOracle+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreMay 13, 2026 Aug 8, 2017 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulner...Show more |
4Debian MariadbOracle+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreMay 13, 2026 Aug 8, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vul...Show more |
4Debian MariadbOracle+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreMay 13, 2026 Aug 8, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerab...Show more |
4Debian MariadbOracle+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreMay 13, 2026 Aug 8, 2017 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.56 and earlier and 5.6.36 and earlier. Easily exploitable vulnerability allows low...Show more |
4Debian NetappOracle+1 more27Active Iq Unified Manager Cloud BackupDebian Linux+24 moreMay 13, 2026 Aug 8, 2017 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28....Show more |
5Debian NetappOracle+2 more27Active Iq Unified Manager Cloud BackupDebian Linux+24 moreMay 13, 2026 Aug 8, 2017 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R2...Show more |
4Debian NetappOracle+1 more25Active Iq Unified Manager Cloud BackupDebian Linux+22 moreMay 13, 2026 Aug 8, 2017 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit...Show more |
5Debian NetappOracle+2 more27Active Iq Unified Manager Cloud BackupDebian Linux+24 moreMay 13, 2026 Aug 8, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.1...Show more |
5Debian NetappOracle+2 more28Active Iq Unified Manager Cloud BackupDebian Linux+25 moreMay 13, 2026 Aug 8, 2017 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R2...Show more |