CVEs (91)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianMozilla+2 more8Debian Linux Network Security ServicesSolaris+5 moreMay 6, 2026 Jul 6, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine sta...Show more |
4Mozilla NovellOpensuse+1 more8Firefox Firefox EsrOpensuse+5 moreMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML...Show more |
3Mozilla NovellOpensuse7Firefox Firefox EsrOpensuse+4 moreMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of serv...Show more |
3Mozilla NovellOpensuse7Firefox Firefox EsrOpensuse+4 moreMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics da...Show more |
3Mozilla NovellOpensuse5Firefox OpensuseSuse Linux Enterprise Desktop+2 moreMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...Show more |
3Mozilla NovellOpensuse7Firefox Firefox EsrOpensuse+4 moreMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption...Show more |
3Novell OracleSuse5Mysql Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756. |
2Novell Oracle4Mysql Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition. |
2Novell Oracle5Communications Policy Management MysqlSuse Linux Enterprise Desktop+2 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer. |
2Novell Oracle4Mysql Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA. |
4Canonical NovellRedhat+1 more6Enterprise Linux SambaSuse Linux Enterprise Desktop+3 moreMay 6, 2026 Feb 24, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which al...Show more |
6Canonical DebianNovell+3 more8Debian Linux Enterprise LinuxJdk+5 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS. |
6Canonical DebianNovell+3 more9Debian Linux Enterprise LinuxJdk+6 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affe...Show more |
6Canonical DebianNovell+3 more8Debian Linux Enterprise LinuxJdk+5 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. |
4Canonical NovellOpensuse+1 more6Jdk JreOpensuse+3 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries. |
6Canonical DebianNovell+3 more7Debian Linux Enterprise LinuxJdk+4 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. |
7Canonical DebianFedoraproject+4 more10Debian Linux Enterprise LinuxFedora+7 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.4 MEDIUM· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related...Show more |
6Canonical DebianNovell+3 more8Debian Linux Enterprise LinuxJdk+5 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. |
6Canonical LinuxNovell+3 more11Evergreen LinuxLinux Enterprise Real Time Extension+8 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafte...Show more |
7Canonical DebianLinux+4 more10Debian Linux Enterprise LinuxEvergreen+7 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to ki...Show more |