CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execu...Show more |
6Canonical FedoraprojectMozilla+3 more7Fedora FirefoxOpensuse+4 moreMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds w...Show more |
4Canonical FedoraprojectMozilla+1 more5Fedora FirefoxOpensuse+2 moreMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger,...Show more |
4Canonical FedoraprojectMozilla+1 more5Fedora FirefoxOpensuse+2 moreMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execut...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects,...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (o...Show more |
4Canonical FedoraprojectMozilla+1 more5Fedora FirefoxOpensuse+2 moreMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of se...Show more |
4Canonical FedoraprojectMozilla+1 more5Fedora FirefoxOpensuse+2 moreMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibl...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of serv...Show more |
3Canonical OpenstackOpensuse3Neutron OpensuseUbuntu LinuxMay 6, 2026 Apr 28, 2014 N/A· v4 N/A· v3 9.0 HIGH· v2 The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, w...Show more |
1Canonical 2Ubuntu Linux Update ManagerMay 6, 2026 Apr 27, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 thr...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxMay 6, 2026 Apr 23, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conve...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxMay 6, 2026 Apr 23, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protecti...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxMay 6, 2026 Apr 23, 2014 N/A· v4 N/A· v3 5.1 MEDIUM· v2 The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leverag...Show more |
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly crea...Show more |
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors. |
3Canonical DebianOracle4Debian Linux JdkJre+1 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound. |
3Canonical DebianOracle4Debian Linux JdkJre+1 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerab...Show more |
5Canonical DebianIbm+2 more7Debian Linux Forms ViewerJdk+4 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related t...Show more |
3Canonical DebianOracle4Debian Linux JdkJre+1 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXB. |