Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2016-5116
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers …
Debian Linux
after 2.2.1
CRITICAL 9.8
CVE-2016-0749EPSS 8%
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2016-5108EPSS 22%
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause …
Debian Linux
after 2.2.3
CRITICAL 9.8
CVE-2015-7695
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL c…
Debian Linux
after 1.12.15
CRITICAL 9.8
CVE-2014-9746
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in t…
Debian Linux
after 2.5.3
CRITICAL 9.8
CVE-2016-4024
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which…
Debian Linux
after 1.4.8
CRITICAL 9.8
CVE-2016-2195EPSS 6%
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possib…
Debian Linux
after 1.10.10
CRITICAL 9.8
CVE-2016-4422
The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2015-0857
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2016-3074EPSS 37%
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potential…
Debian Linux
5.5.35 / 5.6.21+
CRITICAL 9.8
CVE-2016-1659
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact …
Debian Linux
after 49.0.2623.112
CRITICAL 9.8
CVE-2016-2054EPSS 5%
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary cod…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2015-8710
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds h…
Debian Linux
2.9.3+
CRITICAL 9.8
CVE-2016-2385EPSS 27%
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows r…
Debian Linux
after 4.3.4
CRITICAL 9.8
CVE-2016-3153
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related …
Debian Linux
Patch available
CRITICAL 9.8
CVE-2016-2851EPSS 21%
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and ap…
Debian Linux
after 4.1.0
CRITICAL 9.8
CVE-2014-2323EPSS 62%
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host nam…
Debian Linux
1.4.35+
CRITICAL 9.1
CVE-2012-2239
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity…
Debian Linux
1.4.4 / 1.5.3+
CRITICAL 9.8
CVE-2012-0507 KEVEPSS 98%
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 …
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2010-4344 KEVEPSS 72%
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SM…
Debian Linux
4.70+
CRITICAL 9.8
CVE-2009-4013EPSS 6%
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers …
Lintian
2.3.2+
CRITICAL 9.8
CVE-2009-1151 KEVEPSS 95%
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitr…
Debian Linux
2.11.9.5 / 3.1.3.1+
CRITICAL 9.8
CVE-2008-0062EPSS 10%
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of servic…
Debian Linux
after 1.6.3
CRITICAL 9.8
CVE-2005-3120EPSS 23%
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article…
Debian Linux
after 2.8.6
CRITICAL 9.8
CVE-2005-1689EPSS 11%
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code …
Debian Linux
10.4.2+
CRITICAL 9.8
CVE-2005-0102
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code vi…
Debian Linux
after 2.0.2
CRITICAL 9.8
CVE-2004-0772EPSS 7%
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbit…
Debian Linux
after 1.2.8
CRITICAL 9.8
CVE-2004-0434EPSS 7%
k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing …
Debian Linux
0.6.2+