CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OpensuseXen3Debian Linux OpensuseXenMay 6, 2026 Nov 19, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP...Show more |
3Debian OpensuseXen3Debian Linux OpensuseXenMay 6, 2026 Nov 19, 2014 N/A· v4 N/A· v3 5.4 MEDIUM· v2 The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by lev...Show more |
4Canonical DebianFreedesktop+1 more4Dbus Debian LinuxMageia+1 moreMay 6, 2026 Nov 18, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of fi...Show more |
4Canonical DebianRedhat+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+4 moreMay 6, 2026 Nov 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentat...Show more |
6Apple CanonicalDebian+3 more6Debian Linux HyperionLibcurl+3 moreMay 6, 2026 Nov 15, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that...Show more |
5Canonical DebianQemu+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreMay 6, 2026 Nov 14, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value. |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Nov 14, 2014 N/A· v4 N/A· v3 7.2 HIGH· v2 The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling. |
4Debian LinuxOpensuse+1 more5Debian Linux EvergreenLinux Enterprise Real Time Extension+2 moreMay 6, 2026 Nov 10, 2014 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service...Show more |
7Canonical DebianLinux+4 more10Debian Linux Enterprise LinuxEvergreen+7 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to ki...Show more |
8Canonical DebianLinux+5 more12Debian Linux Enterprise MrgEvergreen+9 moreMay 6, 2026 Nov 10, 2014 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks tha...Show more |
7Canonical DebianLinux+4 more10Debian Linux Enterprise LinuxEnterprise Mrg+7 moreMay 6, 2026 Nov 10, 2014 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c...Show more |
7Canonical DebianLinux+4 more7Debian Linux Enterprise LinuxEvergreen+4 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. |
6Canonical DebianLinux+3 more6Debian Linux Enterprise LinuxEvergreen+3 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 4.7 MEDIUM· v2 arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafte...Show more |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreMay 6, 2026 Nov 10, 2014 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging inco...Show more |
5Canonical DebianLinux+2 more5Debian Linux EvergreenLinux Kernel+2 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to caus...Show more |
4Canonical DebianQemu+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+4 moreMay 6, 2026 Nov 7, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which trigger...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux OpensuseQuassel Irc+1 moreMay 6, 2026 Nov 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string. |
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxMay 6, 2026 Nov 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other imp...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxMay 6, 2026 Nov 5, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service...Show more |
5Apple CanonicalDebian+2 more5Debian Linux Enterprise LinuxLibxml2+2 moreMay 6, 2026 Nov 4, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a c...Show more |