CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectNih+2 more5Debian Linux FedoraLibzip+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remot...Show more |
5Canonical DebianOpensuse+2 more5Debian Linux OpensusePhp+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent att...Show more |
6Apple CanonicalDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact...Show more |
5Canonical DebianLibgd+2 more5Debian Linux LibgdOpensuse+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a craft...Show more |
3Debian File ProjectPhp3Debian Linux FilePhpMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, w...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Mar 27, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory...Show more |
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset UR...Show more |
6Canonical DebianDjangoproject+3 more6Debian Linux DjangoFedora+3 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scr...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. |
3Apache DebianFedoraproject3Debian Linux FedoraXerces C++May 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data. |
3Canonical DebianX3Debian Linux LibxfontUbuntu LinuxMay 6, 2026 Mar 20, 2015 N/A· v4 N/A· v3 8.5 HIGH· v2 The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denia...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Mar 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have u...Show more |
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by chang...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Mar 16, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows loc...Show more |
3Debian FedoraprojectLibssh23Debian Linux FedoraLibssh2May 6, 2026 Mar 13, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet. |
3Debian FedoraprojectXen3Debian Linux FedoraXenMay 6, 2026 Mar 12, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenMay 6, 2026 Mar 12, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors. |
3Bestpractical DebianFedoraproject3Debian Linux FedoraRequest TrackerMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors. |
3Bestpractical DebianFedoraproject3Debian Linux FedoraRequest TrackerMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 7.1 HIGH· v2 The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email. |
4Debian MageiaOpensuse+1 more4Debian Linux MageiaOpensuse+1 moreMay 6, 2026 Mar 8, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infin...Show more |