CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache CanonicalFedoraproject+1 more4Enterprise Manager Ops Center FedoraHttp Server+1 moreMay 6, 2026 Dec 29, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within differ...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLibssh+2 moreMay 6, 2026 Dec 29, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet. |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial...Show more |
6Fedoraproject MariadbOpensuse+3 more11Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+8 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero...Show more |
4Fedoraproject OpenstackOpensuse+1 more4Fedora HorizonOpensuse+1 moreMay 6, 2026 Dec 12, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service...Show more |
Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality. |
4Debian FedoraprojectMageia Project+1 more4Debian Linux FedoraMageia+1 moreMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999". |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 3.6 LOW· v2 Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted f...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted i...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a t...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an EL...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record. |
3Debian FedoraprojectLsyncd Project3Debian Linux FedoraLsyncdMay 6, 2026 Dec 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. |
3Fedoraproject OpensuseOpenvas3Fedora OpensuseOpenvas ManagerMay 6, 2026 Dec 3, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibreoffice+1 moreMay 6, 2026 Nov 26, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file. |
6Apache DebianDrupal+3 more6Debian Linux DrillDrupal+3 moreMay 6, 2026 Nov 24, 2014 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. |
3Fedoraproject OpenstackRedhat3Fedora NeutronOpenstackMay 6, 2026 Nov 24, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration. |
3Bundler FedoraprojectOpensuse3Bundler FedoraOpensuseMay 6, 2026 Oct 31, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source. |