CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Oct 24, 2013 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block dev...Show more |
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in...Show more |
3Redhat Ruby LangRubygems3Enterprise Linux RubyRubygemsApr 29, 2026 Oct 17, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 throu...Show more |
3Fedoraproject LinuxRedhat4Enterprise Linux Enterprise MrgFedora+1 moreApr 29, 2026 Oct 10, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple request...Show more |
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vul...Show more |
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvall...Show more |
2Lennart Poettering Redhat2Enterprise Linux RkitApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 4.6 MEDIUM· v2 RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race cond...Show more |
2Redhat Spice Gtk Project2Enterprise Linux Spice GtkApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 4.6 MEDIUM· v2 spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUni...Show more |
2Canonical Redhat3Enterprise Linux LibvirtUbuntu LinuxApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 4.6 MEDIUM· v2 libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck v...Show more |
4Canonical OpensusePolkit Project+1 more4Enterprise Linux OpensusePolkit+1 moreApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 7.2 HIGH· v2 Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1)...Show more |
1Redhat 4Enterprise Linux Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+1 moreApr 29, 2026 Oct 1, 2013 N/A· v4 N/A· v3 7.2 HIGH· v2 Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6...Show more |
2Canonical Redhat3Enterprise Linux LibvirtUbuntu LinuxApr 29, 2026 Sep 30, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denia...Show more |
3Jeff Ortel OpensuseRedhat3Enterprise Linux OpensuseSudsApr 29, 2026 Sep 23, 2013 N/A· v4 N/A· v3 1.2 LOW· v2 cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/. |
3Apple PhpRedhat3Enterprise Linux Mac Os XPhpApr 29, 2026 Sep 16, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, rel...Show more |
4Canonical Mesa3dOpensuse+1 more4Enterprise Linux MesaOpensuse+1 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger...Show more |
3Canonical PhpRedhat3Enterprise Linux PhpUbuntu LinuxApr 29, 2026 Aug 18, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509...Show more |
5Canonical FedoraprojectOpensuse+2 more5Enterprise Linux FedoraOpensuse+2 moreApr 29, 2026 Aug 6, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) v...Show more |
4Canonical HaxxOpensuse+1 more5Curl Enterprise LinuxLibcurl+2 moreApr 29, 2026 Jul 31, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more |
10Fedoraproject FreebsdHp+7 more12Bind Business ServerDnsco Bind+9 moreApr 29, 2026 Jul 29, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause...Show more |
A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which...Show more |