CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly exe...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced,...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxApr 23, 2026 Nov 22, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image. |
2Canonical Openldap2Openldap Ubuntu LinuxApr 23, 2026 Nov 7, 2006 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure. |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 23, 2026 Oct 17, 2006 N/A· v4 N/A· v3 2.1 LOW· v2 Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a...Show more |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxApr 23, 2026 Oct 10, 2006 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket b...Show more |
3Canonical LinuxRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 23, 2026 Oct 5, 2006 N/A· v4 7.5 HIGH· v3 3.3 LOW· v2 The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a...Show more |
3Canonical DebianOpenssl3Debian Linux OpensslUbuntu LinuxApr 23, 2026 Sep 28, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that...Show more |
3Apple CanonicalIsc4Bind Mac Os XMac Os X Server+1 moreApr 16, 2026 Sep 6, 2006 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned. |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 16, 2026 Aug 31, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vu...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Aug 21, 2006 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time." |
3Apache CanonicalDebian3Debian Linux Http ServerUbuntu LinuxApr 16, 2026 Jul 28, 2006 N/A· v4 N/A· v3 7.6 HIGH· v2 Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to caus...Show more |
4Apache CanonicalDebian+1 more5Debian Linux Enterprise Linux ServerEnterprise Linux Workstation+2 moreApr 16, 2026 Jul 28, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP r...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Jul 5, 2006 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via...Show more |
3Canonical DebianFreetype3Debian Linux FreetypeUbuntu LinuxApr 16, 2026 May 30, 2006 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. |
2Canonical Lksctp2Stream Control Transmission Protocol Ubuntu LinuxApr 16, 2026 May 9, 2006 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which lead...Show more |
2Canonical Mozilla4Firefox Mozilla SuiteSeamonkey+1 moreApr 16, 2026 Apr 14, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend...Show more |
2Canonical Mozilla4Firefox Mozilla SuiteSeamonkey+1 moreApr 16, 2026 Apr 14, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, the...Show more |