CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianMozilla+4 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation informat...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information f...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of serv...Show more |
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 Mar 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other...Show more |
5Contec DebianLighttpd+2 more6Debian Linux LighttpdLinux Enterprise High Availability Extension+3 moreMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_che...Show more |
4Debian LighttpdOpensuse+1 more5Debian Linux LighttpdLinux Enterprise High Availability Extension+2 moreMay 6, 2026 Mar 14, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname. |
5Canonical DebianFile Project+2 more5Debian Linux FileOpensuse+2 moreMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable. |
4Canonical DebianFedoraproject+1 more4Cups Filters Debian LinuxFedora+1 moreMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF...Show more |
4Canonical DebianFedoraproject+1 more4Cups Filters Debian LinuxFedora+1 moreMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, whic...Show more |
4Canonical DebianFedoraproject+1 more4Cups Filters Debian LinuxFedora+1 moreMay 6, 2026 Mar 14, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file. |
3Debian GoogleNodejs4Chrome Debian LinuxNode.js+1 moreApr 29, 2026 Mar 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Apache DebianOracle3Debian Linux SolarisTomcatApr 29, 2026 Feb 26, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml,...Show more |
4Canonical DebianFine Free File Project+1 more4Debian Linux Fine Free FilePhp+1 moreApr 29, 2026 Feb 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file. |
5Canonical DebianOpensuse+2 more6Debian Linux LeapLibyaml+3 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code vi...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux Enterprise Manager Ops CenterFedora+10 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux Enterprise Manager Ops CenterFedora+10 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products,...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitiv...Show more |
7Canonical DebianFedoraproject+4 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreApr 29, 2026 Feb 6, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary c...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitra...Show more |