CVEs (1,454)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical LinuxOpensuse+2 more6Esx Linux KernelOpensuse+3 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information f...Show more |
5Canonical DebianLinux+2 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 moreApr 29, 2026 Sep 21, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of t...Show more |
6Avaya CanonicalLinux+3 more13Aura Communication Manager Aura Presence ServicesAura Session Manager+10 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to o...Show more |
5Debian FedoraprojectLinux+2 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreApr 29, 2026 Sep 8, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attacke...Show more |
4Canonical LinuxOpensuse+1 more6Linux Enterprise Desktop Linux Enterprise Real Time ExtensionLinux Enterprise Server+3 moreApr 29, 2026 Sep 8, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise High Availability Extension+4 moreApr 29, 2026 Sep 8, 2010 N/A· v4 N/A· v3 1.9 LOW· v2 The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4...Show more |
7Avaya CanonicalDebian+4 more15Aura Communication Manager Aura Presence ServicesAura Session Manager+12 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more |
4Canonical LinuxOpensuse+1 more5Linux Enterprise Desktop Linux Enterprise ServerLinux Kernel+2 moreApr 29, 2026 Sep 3, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NUL...Show more |
lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate atta...Show more |
3Mozilla OpensuseSuse7Firefox Linux Enterprise DesktopLinux Enterprise Server+4 moreApr 29, 2026 Jul 30, 2010 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a la...Show more |
4Apple OpenldapOpensuse+1 more5Esxi Mac Os XMac Os X Server+2 moreApr 29, 2026 Jul 28, 2010 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and po...Show more |
3Canonical GoogleOpensuse3Chrome OpensuseUbuntu LinuxApr 29, 2026 Jul 6, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecifi...Show more |
8Apple CanonicalDebian+5 more12Debian Linux FedoraIphone Os+9 moreApr 29, 2026 Jun 30, 2010 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Sca...Show more |
10Apple CanonicalDebian+7 more17Chrome Debian LinuxFedora+14 moreApr 29, 2026 Jun 30, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data r...Show more |
3Google OpensuseSuse4Chrome OpensuseSuse Linux Enterprise Desktop+1 moreApr 29, 2026 Jun 15, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remot...Show more |
3Google OpensuseSuse4Chrome OpensuseSuse Linux Enterprise Desktop+1 moreApr 29, 2026 Jun 15, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerH...Show more |
3Google OpensuseSuse4Chrome OpensuseSuse Linux Enterprise Desktop+1 moreApr 29, 2026 Jun 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that...Show more |
5Apple CanonicalGoogle+2 more7Chrome OpensuseSafari+4 moreApr 29, 2026 Jun 11, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has...Show more |
6Apache CanonicalDebian+3 more6Debian Linux FedoraLinux Enterprise Desktop+3 moreApr 29, 2026 Jun 10, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code e...Show more |
3Adobe OpensuseSuse5Acrobat AirFlash Player+2 moreApr 21, 2026 Jun 8, 2010 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute...Show more |