CVEs (1,928)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Enterprise Linux Fedora CoreApr 23, 2026 Apr 16, 2007 N/A· v4 N/A· v3 4.9 MEDIUM· v2 lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked. |
8Mandrakesoft OpenbsdRedhat+5 more12Enterprise Linux Enterprise Linux DesktopFedora Core+9 moreApr 23, 2026 Apr 6, 2007 N/A· v4 N/A· v3 3.8 LOW· v2 Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overfl...Show more |
7Mandrakesoft OpenbsdRedhat+4 more9Enterprise Linux Enterprise Linux DesktopLibxfont+6 moreApr 23, 2026 Apr 6, 2007 N/A· v4 N/A· v3 8.5 HIGH· v2 Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts,...Show more |
pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges. |
The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which d...Show more |
2Ekiga Redhat3Ekiga Enterprise LinuxEnterprise Linux DesktopApr 23, 2026 Feb 20, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled...Show more |
2Linux Redhat3Enterprise Linux Enterprise Linux DesktopLinux KernelApr 23, 2026 Jan 30, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors. |
6Gnu Gpg4winRedhat+3 more9Enterprise Linux Enterprise Linux DesktopFedora Core+6 moreApr 23, 2026 Dec 7, 2006 N/A· v4 N/A· v3 10.0 HIGH· v2 A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a funct...Show more |
The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm...Show more |
3Debian FedoraprojectRedhat8Debian Linux Enterprise LinuxEnterprise Linux Desktop+5 moreApr 23, 2026 Oct 10, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse cont...Show more |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxApr 23, 2026 Oct 10, 2006 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket b...Show more |
A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information. |
2Kde Redhat3Enterprise Linux Enterprise Linux DesktopKdeApr 16, 2026 Jul 27, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop. |
initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges vi...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null derefer...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated usi...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDe...Show more |
2Gnu Redhat4Enterprise Linux Enterprise Linux DesktopLinux Advanced Workstation+1 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 2.6 LOW· v2 The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files v...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Dec 22, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Oct 25, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash). |