CVEs (1,454)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical MozillaOpensuse+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and tri...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remo...Show more |
4Canonical MozillaOpensuse+1 more5Firefox OpensuseSeamonkey+2 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibl...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of serv...Show more |
3Canonical OpensuseRedhat3Icedtea Web OpensuseUbuntu LinuxApr 29, 2026 Feb 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended...Show more |
5Adobe GoogleOpensuse+2 more9Chrome Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 21, 2026 Feb 5, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unsp...Show more |
3Canonical KdeOpensuse4Ark Kde ScOpensuse+1 moreApr 29, 2026 Feb 4, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file. |
3Dest Unreach FedoraprojectOpensuse3Fedora OpensuseSocatApr 29, 2026 Feb 4, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the c...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Jan 28, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or p...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Jan 28, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or...Show more |
2Lightdm Gtk+ Greeter Project Opensuse2Lightdm Gtk+ Greeter OpensuseApr 29, 2026 Jan 23, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local user...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 Jan 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux OpensusePixman+1 moreApr 29, 2026 Jan 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value. |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Jan 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibl...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Jan 16, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X an...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Jan 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to cause a denial of service or possibly have other impact via unknown ve...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Jan 16, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers...Show more |
Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on...Show more |
3Cisco FedoraprojectOpensuse3Fedora LibsrtpOpensuseApr 29, 2026 Jan 16, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and...Show more |
The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and po...Show more |