CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to inject arbitr...Show more |
5Apple CanonicalDebian+2 more6Curl Debian LinuxEnterprise Manager Ops Center+3 moreMay 6, 2026 May 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the heade...Show more |
4Canonical DebianGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop Supplementary+4 moreMay 6, 2026 May 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
4Canonical DebianGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop Supplementary+4 moreMay 6, 2026 May 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cau...Show more |
3Debian OpensuseXiph3Debian Linux IcecastOpensuseMay 6, 2026 Apr 29, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as de...Show more |
5Debian FedoraprojectOpensuse+2 more9Debian Linux FedoraLinux Enterprise Desktop+6 moreMay 6, 2026 Apr 28, 2015 N/A· v4 N/A· v3 2.9 LOW· v2 Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist requ...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+7 moreMay 6, 2026 Apr 28, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management fram...Show more |
6Apache CanonicalDebian+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 6, 2026 Apr 28, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP docum...Show more |
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.26...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly h...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or poss...Show more |
3Canonical DebianPoint To Point Protocol Project3Debian Linux Point To Point ProtocolUbuntu LinuxMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) v...Show more |
7Apple CanonicalDebian+4 more8Curl Debian LinuxFedora+5 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request. |
8Apple CanonicalDebian+5 more9Curl Debian LinuxFedora+6 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly hav...Show more |
4Canonical DebianHaxx+1 more5Curl Debian LinuxLibcurl+2 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly hav...Show more |
5Apple CanonicalDebian+2 more6Curl Debian LinuxLibcurl+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015. |
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (m...Show more |
3Debian LinuxSuse3Debian Linux Linux KernelSuse Linux Enterprise ServerMay 6, 2026 Apr 21, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a d...Show more |