Search

Found 599 results in 118ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-47337 low 3.3 3.3 FIX ubuntu ubuntudebian debian 6d ago Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local u…
CVE-2026-47336 low 3.3 3.3 FIX ubuntu ubuntudebian debian 6d ago Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and…
CVE-2026-31431 high 7.8 10.0 KEVEXPFIX rhelarch arch sles redhatsusearista 1mo ago Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
CVE-2026-3497 high 7.5 7.5 FIX rocky rhel sles canonicalopenbsd 2mo ago Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH u…
CVE-2024-6387 high 8.1 9.1 EXPFIX rhelarch arch sles openbsdredhatnetapp 2y ago A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote a…
CVE-2023-4911 high 7.8 10.0 KEVEXPFIX rhel rocky sles gnuredhatnetapp 3y ago GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileg…
CVE-2019-18197 high 7.5 7.5 FIX arch arch slesdebian debian xmlsoft 4y ago RHSA-2020:4464: libxslt security update (Moderate)
CVE-2014-0056 low 2.1 FIX ubuntu ubuntudebian debian openstack 4y ago The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants …
CVE-2016-9014 high 8.1 8.1 FIX slesarch archubuntu ubuntu djangoproject 4y ago Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validat…
CVE-2015-7529 high 7.8 7.8 FIX rhelubuntu ubuntudebian debian sos_project 4y ago sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by so…
CVE-2017-5936 high 7.5 7.5 ubuntu ubuntu openstack 4y ago OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restriction…
CVE-2022-0492 high 7.8 10.0 KEVEXPFIX sles rockydebian debian redhatnetapp 4y ago Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
CVE-2018-17958 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu qemuredhat 8y ago Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
CVE-2016-10708 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu openbsdnetapp 9y ago sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, relat…
CVE-2017-7160 high 8.8 8.8 FIX slesubuntu ubuntumacos macos apple 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected…
CVE-2017-17879 high 8.8 8.8 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error.
CVE-2017-16995 high 7.8 8.8 EXPFIX arch archdebian debian linux-kernel 9y ago The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by lev…
CVE-2017-17818 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c.
CVE-2017-17806 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_A…
CVE-2017-17805 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYP…
CVE-2017-17789 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
CVE-2017-17787 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
CVE-2017-17786 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
CVE-2017-17785 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
CVE-2017-17784 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
CVE-2017-1000407 high 7.4 7.4 FIX slesarch archdebian debian redhat 9y ago The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
CVE-2017-13168 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 9y ago An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.
CVE-2017-15868 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 9y ago The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a craf…
CVE-2016-1255 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu debian 9y ago The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, i…
CVE-2017-16612 high 7.5 7.5 FIX arch arch slesdebian debian x 9y ago libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack ve…
CVE-2017-15275 high 7.5 7.5 FIX arch arch slesdebian debian samba 9y ago Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
CVE-2017-14176 high 8.8 8.8 FIX debian debian slesubuntu ubuntu canonical 9y ago Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-…
CVE-2017-16544 high 8.8 8.8 FIX arch archdebian debian sles busybox 9y ago In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and res…
CVE-2017-15115 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of…
CVE-2017-16642 high 7.5 8.5 EXP slesdebian debianubuntu ubuntu phpnetapp 9y ago In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to …
CVE-2017-16546 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uni…
CVE-2017-16526 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafte…
CVE-2017-15908 high 7.5 7.5 FIX slesubuntu ubuntudebian debian systemd_project 9y ago In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-re…
CVE-2013-3567 high 7.5 FIX slesubuntu ubuntususe suse puppetpuppetlabs 9y ago Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arb…
CVE-2017-13082 high 8.1 8.1 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing …
CVE-2017-15281 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "…
CVE-2017-2888 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu libsdl 9y ago An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocate…
CVE-2017-15033 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c.
CVE-2017-15017 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/png.c.
CVE-2017-15016 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadEnhMetaFile in coders/emf.c.
CVE-2017-15015 high 8.8 8.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDelegateMessage in coders/pdf.c.
CVE-2017-14496 high 7.5 8.5 EXPFIX arch archdebian debianubuntu ubuntu thekelleys 9y ago Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service …
CVE-2017-14495 high 7.5 8.5 EXPFIX arch arch slesdebian debian thekelleys 9y ago Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involvi…
CVE-2017-13704 high 7.5 7.5 FIX debian debianubuntu ubuntufedora fedora thekelleys 9y ago In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0x…
CVE-2015-3643 high 7.8 8.8 EXP ubuntu ubuntu usb-creator_project 9y ago usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local…
CVE-2015-1336 high 7.8 8.8 EXPFIX debian debianubuntu ubuntu man-db_project 9y ago The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
CVE-2017-14607 high 8.1 8.1 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploit this flaw to disclose potentially sensitive memo…
CVE-2015-1329 high 8.8 8.8 ubuntu ubuntu 9y ago Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.
CVE-2017-6362 high 7.5 7.5 FIX slesdebian debianfedora fedora libgd 9y ago Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
CVE-2017-0902 high 8.1 8.1 FIX slesdebian debian rhel rubygems 9y ago RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacke…
CVE-2017-0901 high 7.5 8.5 EXPFIX slesdebian debian rhel rubygems 9y ago RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
CVE-2015-1395 high 7.5 7.5 FIX fedora fedoraubuntu ubuntudebian debian gnu 9y ago Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a…
CVE-2015-1325 high 7.0 8.0 EXP ubuntu ubuntu 9y ago Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and befo…
CVE-2015-1324 high 7.8 7.8 ubuntu ubuntu 9y ago Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17…
CVE-2017-12836 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnu 9y ago CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand…
CVE-2016-6796 high 7.5 7.5 slesdebian debian rhel apachenetapporacle 9y ago Apache Tomcat vulnerable to SecurityManager bypass
CVE-2016-6797 high 7.5 7.5 slesdebian debian rhel apacheoraclenetapp 9y ago Incorrect Authorization in Apache Tomcat
CVE-2011-5325 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu busybox 9y ago Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
CVE-2015-1332 high 8.8 8.8 ubuntu ubuntu oxide_project 9y ago The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute a…
CVE-2017-7980 high 7.8 7.8 FIX sles rhelubuntu ubuntu qemuredhat 9y ago Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vec…
CVE-2017-11591 high 7.5 7.5 FIX slesarch archdebian debian exiv2 9y ago There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
CVE-2015-5300 high 7.5 7.5 FIX rhelubuntu ubuntufedora fedora susentp 9y ago The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to…
CVE-2015-5219 high 7.5 7.5 FIX rhelubuntu ubuntufedora fedora susentp 9y ago The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infin…
CVE-2015-5195 high 7.5 7.5 FIX slesdebian debian rhel ntp 9y ago ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled …
CVE-2015-5194 high 7.5 7.5 FIX slesdebian debian rhel susentp 9y ago The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
CVE-2017-11473 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 9y ago Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.
CVE-2017-1000050 high 7.5 7.5 slesubuntu ubuntu rhel jasper_project 9y ago JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
CVE-2017-11111 high 7.8 7.8 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a …
CVE-2017-10686 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function…
CVE-2017-9985 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecifi…
CVE-2015-5180 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnu 9y ago res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
CVE-2017-9935 high 8.8 8.8 FIX arch arch slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can…
CVE-2017-9022 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu strongswan 9y ago The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and …
CVE-2017-8386 high 8.8 8.8 FIX arch arch slesdebian debian git 9y ago git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.…
CVE-2016-9842 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu zliboracleredhat 9y ago The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
CVE-2016-9840 high 8.8 8.8 FIX sles rockydebian debian boostzliboracle 9y ago RHSA-2025:8395: rsync security update (Low)
CVE-2017-7645 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu 9y ago The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c,…
CVE-2017-7889 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 9y ago The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the f…
CVE-2016-6489 high 7.5 7.5 FIX slesubuntu ubuntu rhel nettle_project 9y ago The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
CVE-2016-0727 high 7.8 8.8 EXPFIX ubuntu ubuntudebian debian 9y ago The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3…
CVE-2015-8567 high 7.7 7.7 FIX slesdebian debianubuntu ubuntu qemususe 9y ago Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
CVE-2017-7358 high 7.3 8.3 EXPFIX arch archdebian debianubuntu ubuntu lightdm_project 9y ago In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user …
CVE-2017-6964 high 7.8 7.8 ubuntu ubuntudebian debian 9y ago dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute cod…
CVE-2016-9243 high 7.5 7.5 FIX ubuntu ubuntufedora fedoradebian debian cryptography.io 9y ago HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
CVE-2016-9775 high 7.8 7.8 ubuntu ubuntudebian debian apache 9y ago The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 L…
CVE-2016-9774 high 7.8 7.8 ubuntu ubuntudebian debian apache 9y ago The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7…
CVE-2014-9851 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
CVE-2014-9850 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
CVE-2014-9849 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
CVE-2014-9848 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
CVE-2014-9842 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
CVE-2017-7184 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain r…
CVE-2014-9854 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
CVE-2017-6960 high 7.5 7.5 FIX debian debianubuntu ubuntu apng2gif_project 9y ago An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable.
CVE-2017-5669 high 7.8 7.8 FIX slesdebian debian linux-kernel 9y ago The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and conseque…