CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianOpensuse+2 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Nov 1, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. |
4Canonical DebianOpensuse+1 more4Debian Linux OpensusePidgin+1 moreMay 6, 2026 Oct 29, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates fr...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxOpensuseMay 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxOpensuseMay 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action. |
3Canonical DebianGnu3Debian Linux GpgmeUbuntu LinuxMay 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute a...Show more |
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array con...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreMay 6, 2026 Oct 16, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame. |
4Canonical DebianMageia+1 more4Debian Linux MageiaRequests+1 moreMay 6, 2026 Oct 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request. |
11Apple DebianFedoraproject+8 more20Aix DatabaseDebian Linux+17 moreMay 28, 2026 Oct 15, 2014 N/A· v4 3.4 LOW· v3 4.3 MEDIUM· v2 The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a...Show more |
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extrac...Show more |
3Canonical DebianMageia4Debian Linux Exuberant CtagsMageia+1 moreMay 6, 2026 Oct 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file. |
3Canonical DebianLibvncserver3Debian Linux LibvncserverUbuntu LinuxMay 6, 2026 Oct 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in th...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 6.1 MEDIUM· v2 Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via...Show more |
4Debian FedoraprojectLibvncserver+1 more5Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+2 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary cod...Show more |
5Debian FedoraprojectLibvncserver+2 more6Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 25, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 24, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more |
5Canonical DebianLua+2 more5Debian Linux LuaMageia+2 moreMay 6, 2026 Sep 4, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large nu...Show more |
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related t...Show more |