Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2015-5261
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL com…
Ubuntu Linux
Mitigation only
MEDIUM 6.5
CVE-2016-1702
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval coun…
Ubuntu Linux
after 51.0.2704.63
MEDIUM 6.5
CVE-2016-1699
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, …
Ubuntu Linux
after 51.0.2704.63
MEDIUM 5.3
CVE-2016-1692
WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets…
Ubuntu Linux
after 50.0.2661.102
HIGH 7.5
CVE-2016-1691
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-bas…
Ubuntu Linux
after 50.0.2661.102
MEDIUM 6.5
CVE-2016-1689
Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause …
Ubuntu Linux
after 50.0.2661.102
MEDIUM 6.5
CVE-2016-1688
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external s…
Ubuntu Linux
after 50.0.2661.102
HIGH 7.5
CVE-2016-1683
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause …
Ubuntu Linux
after 50.0.2661.102
HIGH 8.8
CVE-2016-1675
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Docume…
Ubuntu Linux
after 50.0.2661.102
MEDIUM 6.2
CVE-2016-4804
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which trigg…
Ubuntu Linux
after 3.0.28
MEDIUM 6.2
CVE-2015-8872
The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memo…
Ubuntu Linux
after 3.0.28
HIGH 7.8
CVE-2016-5126
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU pr…
Ubuntu Linux
Patch available
MEDIUM 6.0
CVE-2016-4454
The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information…
Ubuntu Linux
after 2.6.0
MEDIUM 6.5
CVE-2016-4020
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to ob…
Ubuntu Linux
Patch available
HIGH 8.6
CVE-2016-4001
Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to ac…
Ubuntu Linux
after 2.5.1.1
HIGH 7.8
CVE-2016-4913
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 cha…
Ubuntu Linux
3.2.81 / 3.10.102+
MEDIUM 5.5
CVE-2016-4581
fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allo…
Ubuntu Linux
after 4.5.3
HIGH 7.5
CVE-2016-4485
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers t…
Ubuntu Linux
after 4.5.4
MEDIUM 6.2
CVE-2016-4482
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows …
Ubuntu Linux
after 4.6
MEDIUM 6.0
CVE-2016-4441
The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local …
Ubuntu Linux
after 2.6.0
MEDIUM 6.7
CVE-2016-4439
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, wh…
Ubuntu Linux
after 2.6.0
MEDIUM 5.5
CVE-2016-1839EPSS 7%
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before …
Ubuntu Linux
Patch available
MEDIUM 5.5
CVE-2016-1838EPSS 7%
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, an…
Ubuntu Linux
Patch available
MEDIUM 5.5
CVE-2016-1837
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in …
Ubuntu Linux
Patch available
MEDIUM 5.5
CVE-2016-1836
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, t…
Ubuntu Linux
Patch available
HIGH 8.8
CVE-2016-1835EPSS 6%
Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, a…
Ubuntu Linux
after 10.11.4
HIGH 7.8
CVE-2016-1834
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.…
Ubuntu Linux
Patch available
HIGH 7.5
CVE-2016-3705EPSS 5%
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth…
Ubuntu Linux
Mitigation only
CRITICAL 9.8
CVE-2016-1580
The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when usi…
Ubuntu Core Launcher
Mitigation only
CRITICAL 9.8
CVE-2016-1578
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecif…
Ubuntu Linux
Mitigation only