CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the textu...Show more |
3Canonical MozillaOpensuse4Firefox LeapOpensuse+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL. |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu. |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or...Show more |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG...Show more |
6Canonical DebianMozilla+3 more21Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+18 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
4Canonical MozillaNovell+1 more7Firefox LeapOpensuse+4 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...Show more |
7Canonical DebianGraphicsmagick+4 more14Debian Linux GraphicsmagickImagemagick+11 moreMay 6, 2026 Jun 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. |
3Canonical GnuOpensuse4Glibc LeapOpensuse+1 moreMay 6, 2026 Jun 10, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via...Show more |
3Canonical DebianXmlsoft3Debian Linux Libxml2Ubuntu LinuxMay 6, 2026 Jun 9, 2016 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a d...Show more |
7Apple CanonicalDebian+4 more11Debian Linux Icewall Federation AgentIphone Os+8 moreMay 6, 2026 Jun 9, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlPa...Show more |
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecifi...Show more |
LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors. |
3Canonical DebianF53Debian Linux NginxUbuntu LinuxMay 6, 2026 Jun 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a clie...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 7, 2016 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation. |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 7, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands relat...Show more |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-b...Show more |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with...Show more |
6Canonical DebianGoogle+3 more9Chrome Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Jun 5, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which a...Show more |