CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraUbuntu Linux+1 moreMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 4.9 MEDIUM· v2 QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabl...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafte...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly ha...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote att...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::Allocat...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which all...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote at...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome...Show more |
9Canonical DebianFujitsu+6 more619700 Firmware Cognos Metrics ManagerCommunications Application Session Controller+58 moreMay 28, 2026 Apr 1, 2015 N/A· v4 3.7 LOW· v3 5.0 MEDIUM· v2 The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recover...Show more |
5Canonical DebianOpensuse+2 more5Debian Linux OpensusePhp+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent att...Show more |
6Apple CanonicalDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact...Show more |
5Canonical DebianLibgd+2 more5Debian Linux LibgdOpensuse+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a craft...Show more |
3Canonical GnuSuse4Glibc Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreMay 6, 2026 Mar 27, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of ser...Show more |
6Canonical DebianDjangoproject+3 more6Debian Linux DjangoFedora+3 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scr...Show more |
5Canonical DjangoprojectFedoraproject+2 more5Django FedoraOpensuse+2 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by...Show more |
2Canonical Linuxfoundation2Cups Filters Ubuntu LinuxMay 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vu...Show more |
3Apache CanonicalRedhat3Batik Jboss Enterprise Brms PlatformUbuntu LinuxMay 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG f...Show more |
3Canonical DebianX3Debian Linux LibxfontUbuntu LinuxMay 6, 2026 Mar 20, 2015 N/A· v4 N/A· v3 8.5 HIGH· v2 The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denia...Show more |
3Canonical Mageia ProjectPython3Mageia RequestsUbuntu LinuxMay 6, 2026 Mar 18, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect. |