CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
11Apple DebianFedoraproject+8 more20Aix DatabaseDebian Linux+17 moreMay 28, 2026 Oct 15, 2014 N/A· v4 3.4 LOW· v3 4.3 MEDIUM· v2 The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a...Show more |
2Fedoraproject Mozilla2Bugzilla FedoraMay 6, 2026 Oct 13, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote...Show more |
2Fedoraproject Mozilla2Bugzilla FedoraMay 6, 2026 Oct 13, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not s...Show more |
2Fedoraproject Mozilla2Bugzilla FedoraMay 6, 2026 Oct 13, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveragin...Show more |
3Apple FedoraprojectJoyent3Fedora Node.jsXcodeMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "pu...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 6.1 MEDIUM· v2 Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via...Show more |
4Debian FedoraprojectLibvncserver+1 more5Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+2 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary cod...Show more |
5Debian FedoraprojectLibvncserver+2 more6Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement...Show more |
4Fedoraproject GnuMageia+1 more4Fedora MageiaOpensuse+1 moreMay 6, 2026 Aug 20, 2014 N/A· v4 N/A· v3 3.3 LOW· v2 The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file. |
4Canonical FedoraprojectGentoo+1 more4Fedora LinuxTransmission+1 moreMay 6, 2026 Jul 29, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer messag...Show more |
2Fedoraproject Zarafa3Fedora WebappZarafaMay 6, 2026 Jul 29, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files. |
3Apple CanonicalFedoraproject3Cups FedoraUbuntu LinuxMay 6, 2026 Jul 23, 2014 N/A· v4 N/A· v3 1.2 LOW· v2 The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/. |
4Debian FedoraprojectMit+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session. |
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors. |
The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via an empty quoted string in an RFC...Show more |
5Canonical FedoraprojectLibreoffice+2 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx. |
3Cherokee Project FedoraprojectMageia Project3Cherokee FedoraMageiaMay 6, 2026 Jul 2, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authen...Show more |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of s...Show more |
9Fedoraproject Filezilla ProjectMariadb+6 more16Application Processing Engine Firmware Cp1543 1 FirmwareEnterprise Linux+13 moreMay 6, 2026 Jun 5, 2014 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more |