CVEs (1,454)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository no...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-h...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafte...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly ha...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote att...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::Allocat...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which all...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote at...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome...Show more |
9Canonical DebianFujitsu+6 more619700 Firmware Cognos Metrics ManagerCommunications Application Session Controller+58 moreMay 28, 2026 Apr 1, 2015 N/A· v4 3.7 LOW· v3 5.0 MEDIUM· v2 The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recover...Show more |
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command. |
4Apple OpensusePhp+1 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via...Show more |
4Apple OpensusePhp+1 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attac...Show more |
5Debian FedoraprojectNih+2 more5Debian Linux FedoraLibzip+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remot...Show more |
5Canonical DebianOpensuse+2 more5Debian Linux OpensusePhp+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent att...Show more |
6Apple CanonicalDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact...Show more |
5Canonical DebianLibgd+2 more5Debian Linux LibgdOpensuse+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a craft...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Mar 27, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory...Show more |
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header. |