CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Oxide Project2Oxide Ubuntu LinuxMay 6, 2026 Apr 29, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage. |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+7 moreMay 6, 2026 Apr 28, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management fram...Show more |
6Apache CanonicalDebian+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 6, 2026 Apr 28, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP docum...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly h...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or poss...Show more |
3Canonical DebianPoint To Point Protocol Project3Debian Linux Point To Point ProtocolUbuntu LinuxMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) v...Show more |
7Apple CanonicalDebian+4 more8Curl Debian LinuxFedora+5 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request. |
8Apple CanonicalDebian+5 more9Curl Debian LinuxFedora+6 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly hav...Show more |
4Canonical DebianHaxx+1 more5Curl Debian LinuxLibcurl+2 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly hav...Show more |
5Apple CanonicalDebian+2 more6Curl Debian LinuxLibcurl+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015. |
3Canonical DebianGoogle4Chrome Debian LinuxUbuntu Linux+1 moreMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for...Show more |
3Canonical DebianGoogle4Chrome Debian LinuxUbuntu Linux+1 moreMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have...Show more |
6Canonical DebianGoogle+3 more11Chrome Debian LinuxEnterprise Linux Desktop+8 moreMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a c...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors. |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possib...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to...Show more |