CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Cups Filters Debian LinuxFedora+1 moreMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, whic...Show more |
4Canonical DebianFedoraproject+1 more4Cups Filters Debian LinuxFedora+1 moreMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file. |
2Canonical Linuxfoundation2Cups Filters Ubuntu LinuxMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file. |
Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-f...Show more |
2Canonical Freedesktop2Ubuntu Linux UdisksMay 6, 2026 Mar 11, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point. |
4Canonical F5Linux+1 more27Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+24 moreMay 6, 2026 Mar 11, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote...Show more |
2Canonical Robert Ancell2Lightdm Ubuntu LinuxMay 6, 2026 Mar 6, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc. |
2Canonical Debian2Advanced Package Tool Ubuntu LinuxApr 29, 2026 Mar 1, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecif...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain...Show more |
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to s...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet da...Show more |
4Canonical DebianFine Free File Project+1 more4Debian Linux Fine Free FilePhp+1 moreApr 29, 2026 Feb 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file. |
The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via...Show more |
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allo...Show more |
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SO...Show more |
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SO...Show more |
5Canonical DebianOpensuse+2 more6Debian Linux LeapLibyaml+3 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code vi...Show more |
2Canonical Gpsd Project2Gpsd Ubuntu LinuxApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lack...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux Enterprise Manager Ops CenterFedora+10 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux Enterprise Manager Ops CenterFedora+10 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products,...Show more |