CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more6Debian Linux Enterprise LinuxFedora+3 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing. |
6Canonical DebianNovell+3 more7Debian Linux Enterprise LinuxJdk+4 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. |
7Canonical DebianFedoraproject+4 more10Debian Linux Enterprise LinuxFedora+7 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.4 MEDIUM· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related...Show more |
7Canonical DebianFedoraproject+4 more17Communications Policy Management Debian LinuxEnterprise Linux Desktop+14 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability tha...Show more |
7Canonical DebianFedoraproject+4 more17Communications Policy Management Debian LinuxEnterprise Linux Desktop+14 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability tha...Show more |
3Debian OpensuseOracle3Debian Linux OpensuseVm VirtualboxMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 4.4 MEDIUM· v2 Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Cor...Show more |
7Canonical DebianFedoraproject+4 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Forei...Show more |
6Canonical DebianNovell+3 more8Debian Linux Enterprise LinuxJdk+5 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. |
WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit. |
7Canonical DebianFedoraproject+4 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML. |
5Canonical DebianLibsndfile Project+2 more5Debian Linux LibsndfileOpensuse+2 moreMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read. |
4Canonical DebianFedoraproject+1 more4Binutils Debian LinuxFedora+1 moreMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended nam...Show more |
3Canonical DebianHaxx3Debian Linux LibcurlUbuntu LinuxMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in...Show more |
4Debian OpensuseOracle+1 more5Debian Linux LinuxOpensuse+2 moreMay 6, 2026 Jan 10, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application cras...Show more |
7Canonical DebianFedoraproject+4 more19Debian Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism...Show more |
7Canonical DebianLinux+4 more19Debian Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sen...Show more |
6Canonical DebianFedoraproject+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other i...Show more |
The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:...Show more |
2Debian Mantisbt2Debian Linux MantisbtMay 6, 2026 Jan 9, 2015 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline...Show more |
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the...Show more |