Severity: MEDIUM

84400 CVEs found

CVE-2010-2066
5.5 MEDIUM

The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a...

Published: 2010-09-08
Products: 12
Vendors:
linux vmware canonical suse
CVE-2010-2942
5.5 MEDIUM

The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which all...

Published: 2010-09-21
Products: 38
Vendors:
avaya vmware linux canonical suse +1 more
CVE-2010-3078
5.5 MEDIUM

The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sen...

Published: 2010-09-21
Products: 17
Vendors:
vmware linux canonical suse opensuse
CVE-2010-2538
5.5 MEDIUM

Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.

Published: 2010-09-30
Products: 7
Vendors:
linux canonical suse
CVE-2010-3079
5.5 MEDIUM

kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cau...

Published: 2010-09-30
Products: 7
Vendors:
linux canonical suse
CVE-2010-4020
6.3 MEDIUM

MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, an...

Published: 2010-12-02
Products: 4
Vendors:
mit
CVE-2010-4343
5.5 MEDIUM

drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port data structure, which allows local users to cause a denial of service (system crash) via read operation...

Published: 2010-12-29
Products: 3
Vendors:
linux vmware
CVE-2011-0199
5.9 MEDIUM

The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle ...

Published: 2011-06-24
Products: 2
Vendors:
apple
CVE-2009-5078
6.5 MEDIUM

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbit...

Published: 2011-06-30
Products: 16
Vendors:
apple gnu
CVE-2011-2501
6.5 MEDIUM

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (applic...

Published: 2011-07-17
Products: 11
Vendors:
fedoraproject libpng debian canonical
CVE-2011-2691
6.5 MEDIUM

The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empt...

Published: 2011-07-17
Products: 7
Vendors:
fedoraproject libpng debian
CVE-2010-4655
5.5 MEDIUM

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by levera...

Published: 2011-07-18
Products: 4
Vendors:
linux vmware canonical
CVE-2009-4139
6.8 MEDIUM

A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauth...

Published: 2011-07-27
Products: 4
Vendors:
redhat
CVE-2011-1776
6.1 MEDIUM

The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows phys...

Published: 2011-09-06
Products: 6
Vendors:
linux redhat
CVE-2011-4107
6.5 MEDIUM

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary...

Published: 2011-11-17
Products: 6
Vendors:
fedoraproject debian phpmyadmin
CVE-2011-4461
5.3 MEDIUM

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service ...

Published: 2011-12-30
Products: 341
Vendors:
oracle mortbay
CVE-2012-0930
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: 2012-01-28
Products: 1
Vendors:
schneider-electric
CVE-2011-1573
5.9 MEDIUM

net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT an...

Published: 2012-02-02
Products: 1
Vendors:
linux
CVE-2012-0767
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and be...

Published: 2012-02-16
Products: 10
Vendors:
linux oracle microsoft adobe apple +1 more
CVE-2011-3637
5.5 MEDIUM

The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.

Published: 2012-05-17
Products: 2
Vendors:
linux redhat