CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Redcloth2Debian Linux Redcloth LibraryMay 6, 2026 Jan 8, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Jan 7, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025. |
3Debian OracleSound Exchange Project3Debian Linux SolarisSound ExchangeMay 6, 2026 Dec 31, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLibssh+2 moreMay 6, 2026 Dec 29, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet. |
4Apache AppleDebian+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT requ...Show more |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial...Show more |
4Canonical DebianFirebirdsql+1 more4Debian Linux EvergreenFirebird+1 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action...Show more |
2Debian Sixapart2Debian Linux Movable TypeMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrat...Show more |
3Canonical DebianLibvncserver3Debian Linux LibvncserverUbuntu LinuxMay 6, 2026 Dec 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to ca...Show more |
4Canonical DebianLibvncserver+1 more4Debian Linux LibvncserverSolaris+1 moreMay 6, 2026 Dec 15, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application cras...Show more |
3Canonical DebianNlnetlabs3Debian Linux Ubuntu LinuxUnboundMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals. |
2Debian Powerdns2Debian Linux RecursorMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by r...Show more |
2Debian X.org3Debian Linux X11X ServerMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cau...Show more |
2Debian X.org4Debian Linux X11X Server+1 moreMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds r...Show more |
2Debian X.org3Debian Linux X11X ServerMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial...Show more |
2Debian X.org3Debian Linux X11X ServerMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write)...Show more |
3Debian OracleX.org3Debian Linux SolarisX ServerMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (c...Show more |
4Debian FedoraprojectMageia Project+1 more4Debian Linux FedoraMageia+1 moreMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999". |
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain...Show more |