CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectLsyncd Project3Debian Linux FedoraLsyncdMay 6, 2026 Dec 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. |
3Canonical DebianGnu3Debian Linux GlibcUbuntu LinuxMay 6, 2026 Dec 5, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when conv...Show more |
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in a...Show more |
5Canonical DebianMageia+2 more6Debian Linux MageiaOpensuse+3 moreMay 6, 2026 Dec 3, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet. |
4Debian MageiaMutt+1 more5Debian Linux Linux Enterprise DesktopMageia+2 moreMay 6, 2026 Dec 2, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, w...Show more |
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive. |
4Canonical DebianGnupg+1 more5Debian Linux GnupgLibksba+2 moreMay 6, 2026 Dec 1, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP...Show more |
4Debian OpensuseRedhat+1 more5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreMay 6, 2026 Dec 1, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a de...Show more |
3Debian OpensuseXen3Debian Linux OpensuseXenMay 6, 2026 Dec 1, 2014 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving alteri...Show more |
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibreoffice+1 moreMay 6, 2026 Nov 26, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file. |
3Debian Mageia ProjectWordpress3Debian Linux MageiaWordpressMay 6, 2026 Nov 25, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-rese...Show more |
3Debian Mageia ProjectWordpress3Debian Linux MageiaWordpressMay 6, 2026 Nov 25, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for a...Show more |
2Debian Wordpress2Debian Linux WordpressMay 6, 2026 Nov 25, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Styl...Show more |
2Debian Wordpress2Debian Linux WordpressMay 6, 2026 Nov 25, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecifie...Show more |
6Apache DebianDrupal+3 more6Debian Linux DrillDrupal+3 moreMay 6, 2026 Nov 24, 2014 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. |
3Debian OpensuseXen3Debian Linux OpensuseXenMay 6, 2026 Nov 24, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a craf...Show more |
3Debian DrupalSecure Password Hashes Project3Debian Linux DrupalSecure Passwords HashesMay 6, 2026 Nov 24, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) vi...Show more |
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions. |
4Canonical DebianGnu+1 more4Debian Linux GlibcOpensuse+1 moreMay 6, 2026 Nov 24, 2014 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))". |