CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache CanonicalOpensuse+2 more10Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+7 moreApr 29, 2026 Jun 10, 2013 N/A· v4 N/A· v3 5.1 MEDIUM· v2 mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary command...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 29, 2026 Jun 7, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveragin...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 May 29, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and ba...Show more |
1Canonical 2Telepathy Idle Ubuntu LinuxApr 29, 2026 May 21, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate,...Show more |
5Canonical DebianMozilla+2 more18Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+15 moreApr 22, 2026 May 16, 2013 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDO...Show more |
3Canonical ClamavSuse3Clamav Linux Enterprise ServerUbuntu LinuxApr 29, 2026 May 13, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file. |
3Canonical ClamavSuse3Clamav Linux Enterprise ServerUbuntu LinuxApr 29, 2026 May 13, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executa...Show more |
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information,...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxApr 29, 2026 May 2, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumpt...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxApr 29, 2026 May 2, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obta...Show more |
2Canonical Haxx3Curl LibcurlUbuntu LinuxApr 29, 2026 Apr 29, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a U...Show more |
3Canonical OpensuseRedhat3Icedtea Web OpensuseUbuntu LinuxApr 29, 2026 Apr 29, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR." |
3Canonical OpensuseRedhat3Icedtea Web OpensuseUbuntu LinuxApr 29, 2026 Apr 29, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or p...Show more |
3Canonical OpensuseXmlsoft3Libxml2 OpensuseUbuntu LinuxApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to th...Show more |
3Canonical OpensuseOracle3Jre OpensuseUbuntu LinuxApr 22, 2026 Apr 17, 2013 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOT...Show more |
2Canonical Postgresql2Postgresql Ubuntu LinuxApr 29, 2026 Apr 4, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2...Show more |
2Canonical Postgresql2Postgresql Ubuntu LinuxApr 29, 2026 Apr 4, 2013 N/A· v4 N/A· v3 8.5 HIGH· v2 PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspec...Show more |
2Canonical Postgresql2Postgresql Ubuntu LinuxApr 29, 2026 Apr 4, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users...Show more |
5Canonical DebianMozilla+2 more10Debian Linux FirefoxLinux Enterprise Desktop+7 moreApr 29, 2026 Apr 3, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderb...Show more |
4Canonical MozillaOracle+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Apr 3, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMo...Show more |