CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SO...Show more |
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SO...Show more |
2Matthew Booth Redhat2Enterprise Linux Virt V2vApr 29, 2026 Feb 8, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password. |
3Mariadb OracleRedhat6Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreApr 29, 2026 Jan 31, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string. |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Dec 14, 2013 N/A· v4 N/A· v3 6.2 MEDIUM· v2 The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address. |
2Mod Nss Project Redhat2Enterprise Linux Mod NssApr 29, 2026 Dec 12, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access...Show more |
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitr...Show more |
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and po...Show more |
1Redhat 2Enterprise Linux Jboss Enterprise Application PlatformApr 29, 2026 Dec 6, 2013 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, whi...Show more |
2Openfabrics Redhat2Enterprise Linux IbutilsApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 6.3 MEDIUM· v2 OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs,...Show more |
2Opensuse Redhat2Enterprise Linux OpensuseApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command, when using the -i switch, which trigge...Show more |
2Opensuse Redhat2Enterprise Linux OpensuseApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 2.1 LOW· v2 The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command, which triggers a stack-based buffer ov...Show more |
2Opensuse Redhat2Enterprise Linux OpensuseApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch...Show more |
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive i...Show more |
2Fedoraproject Redhat3389 Directory Server Directory ServerEnterprise LinuxApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request. |
2Redhat Scientificlinux2Enterprise Linux LuciApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 6.2 MEDIUM· v2 Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current workin...Show more |
2Redhat Scientificlinux2Enterprise Linux LuciApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "aut...Show more |
3Busybox RedhatT Mobile3Busybox Enterprise LinuxTm Ac1900Apr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 7.2 HIGH· v2 util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors. |
2Clusterlabs Redhat2Enterprise Linux PacemakerApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a d...Show more |
2Redhat Spice Project3Enterprise Linux Enterprise VirtualizationSpiceApr 29, 2026 Nov 2, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket. |