CVEs (22)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem |
7Canonical DebianFedoraproject+4 more20Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+17 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more |
10Canonical DebianFedoraproject+7 more18Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+15 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a craft...Show more |
6Canonical DebianFedoraproject+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+10 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. |
3Novell SuseXen6Manager Manager ProxyOpenstack Cloud+3 moreMay 13, 2026 May 3, 2017 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function....Show more |
4Novell NtpOpensuse+1 more10Leap Linux Enterprise DebuginfoLinux Enterprise Desktop+7 moreMay 13, 2026 Jan 30, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename. |
5Ntp OpensuseOracle+2 more12Leap Linux Enterprise DesktopLinux Enterprise Server+9 moreMay 6, 2026 Jul 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a...Show more |
5Ntp OpensuseOracle+2 more12Leap Linux Enterprise DesktopLinux Enterprise Server+9 moreMay 6, 2026 Jul 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time. |
3Ibm RedhatSuse13Enterprise Linux Desktop Enterprise Linux Hpc Node SupplementaryEnterprise Linux Server+10 moreMay 6, 2026 May 24, 2016 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8...Show more |
6Canonical ImagemagickOpensuse+3 more30Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 moreApr 22, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
6Canonical ImagemagickOpensuse+3 more30Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 moreApr 22, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 5.8 MEDIUM· v2 The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
8Apache CanonicalDebian+5 more38Cassandra Debian LinuxE Series Santricity Management Plug Ins+35 moreApr 22, 2026 Apr 21, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db....Show more |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure an...Show more |
XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vecto...Show more |
9Canonical DebianFujitsu+6 more619700 Firmware Cognos Metrics ManagerCommunications Application Session Controller+58 moreMay 28, 2026 Apr 1, 2015 N/A· v4 3.7 LOW· v3 5.0 MEDIUM· v2 The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recover...Show more |
Cross-site scripting (XSS) vulnerability in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allows remote authenticated users to inject arbitrary web script or HTML via the System Groups field. |
2Redhat Suse3Manager Network SatelliteSpacewalkMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST A...Show more |
2Redhat Suse5Manager Manager ServerSatellite+2 moreMay 6, 2026 Nov 3, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vecto...Show more |
2Redhat Suse5Manager Manager ServerSatellite+2 moreMay 6, 2026 Sep 22, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a c...Show more |