CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical LinuxOpensuse3Linux Kernel OpensuseUbuntu LinuxMay 6, 2026 Jun 7, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a denial of service (sys...Show more |
6Canonical CitrixDebian+3 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreMay 6, 2026 Jun 3, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensiti...Show more |
5Canonical DebianF5+2 more25Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+22 moreMay 6, 2026 May 29, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. |
2Canonical Wouter Verhelst2Nbd Ubuntu LinuxMay 6, 2026 May 29, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors. |
4Apple CanonicalDebian+1 more4Debian Linux Mac Os X ServerPostgresql+1 moreMay 6, 2026 May 28, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL s...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attac...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 1.9 LOW· v2 arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a cra...Show more |
12Apple CanonicalDebian+9 more25Chrome Content ManagerDebian Linux+22 moreMay 27, 2026 May 21, 2015 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgra...Show more |
2Canonical Module Signature Project2Module Signature Ubuntu LinuxMay 6, 2026 May 19, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff modul...Show more |
2Canonical Module Signature Project2Module Signature Ubuntu LinuxMay 6, 2026 May 19, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest. |
2Canonical Module Signature Project2Module Signature Ubuntu LinuxMay 6, 2026 May 19, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 May 12, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) loa...Show more |
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file. |
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file. |
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file. |
The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file. |
5Apple CanonicalDebian+2 more6Curl Debian LinuxEnterprise Manager Ops Center+3 moreMay 6, 2026 May 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the heade...Show more |
4Canonical DebianGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop Supplementary+4 moreMay 6, 2026 May 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
4Canonical DebianGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop Supplementary+4 moreMay 6, 2026 May 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cau...Show more |
2Canonical Ubuntu2Network Manager Ubuntu LinuxMay 6, 2026 Apr 29, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0ubuntu7.1 allows local...Show more |