Oracle
oracle
11,395 CVEs • 1,102 products
Products (1,102)
Click to collapseToggle
Products (1,102)
Click to collapse
CVEs (11,395)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS us...Show more |
7Canonical DebianHp+4 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and applicatio...Show more |
4Debian OraclePhp+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 6, 2026 May 16, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, lea...Show more |
6Debian FedoraprojectMariadb+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 May 16, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof server...Show more |
6Canonical CitrixDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 May 11, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. |
7Canonical CitrixDebian+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 May 11, 2016 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the ban...Show more |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request. |
6Canonical ImagemagickOpensuse+3 more30Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 moreApr 22, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
6Canonical ImagemagickOpensuse+3 more30Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 moreApr 22, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 5.8 MEDIUM· v2 The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
8Apple CanonicalDebian+5 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+12 moreMay 6, 2026 May 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount o...Show more |
3Canonical LinuxOracle3Linux Kernel Ubuntu LinuxVm ServerMay 6, 2026 May 2, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memo...Show more |
4Debian LinuxOracle+1 more4Debian Linux Enterprise LinuxLinux+1 moreMay 6, 2026 Apr 27, 2016 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified ot...Show more |
2Apache Oracle2Siebel E Billing StrutsMay 6, 2026 Apr 26, 2016 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimizatio...Show more |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data. |
3Debian OracleWireshark3Debian Linux SolarisWiresharkMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecif...Show more |