← Back

Linux

linux

Vendor: Oracle • 229 CVEs

CVEs (229)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
OpensuseOracle+1 more
5Debian Linux
LinuxOpensuse+2 more
May 6, 2026
Jan 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application cras...Show more
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.Show less
7Canonical
DebianLinux+4 more
19Debian Linux
Enterprise Linux AusEnterprise Linux Desktop+16 more
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sen...Show more
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.Show less
4Bsd Mailx Project
HeirloomOracle+1 more
4Bsd Mailx
Enterprise LinuxLinux+1 more
May 6, 2026
Dec 24, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
5Canonical
LinuxOpensuse+2 more
6Evergreen
LinuxLinux Kernel+3 more
May 6, 2026
Dec 12, 2014
N/A· v4
3.3 LOW· v3
1.9 LOW· v2
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR prote...Show more
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.Show less
2Oracle
Uninett
2Linux
Mod Auth Mellon
May 6, 2026
Nov 15, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "session...Show more
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."Show less
6Canonical
LinuxNovell+3 more
11Evergreen
LinuxLinux Enterprise Real Time Extension+8 more
May 6, 2026
Nov 10, 2014
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafte...Show more
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.Show less
8Canonical
DebianLinux+5 more
12Debian Linux
Enterprise MrgEvergreen+9 more
May 6, 2026
Nov 10, 2014
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks tha...Show more
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.Show less
7Canonical
DebianLinux+4 more
10Debian Linux
Enterprise LinuxEnterprise Mrg+7 more
May 6, 2026
Nov 10, 2014
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c...Show more
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.Show less
7Canonical
DebianLinux+4 more
7Debian Linux
Enterprise LinuxEvergreen+4 more
May 6, 2026
Nov 10, 2014
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
4Apache
CanonicalOracle+1 more
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and applic...Show more
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.Show less
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 25, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.Show less
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 24, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.Show less
5Debian
File ProjectOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause...Show more
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.Show less
5Debian
File ProjectOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to ca...Show more
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.Show less
5Debian
File ProjectOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to ca...Show more
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.Show less
5Christos Zoulas
DebianOpensuse+2 more
5Debian Linux
FileLinux+2 more
May 6, 2026
Jul 9, 2014
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and...Show more
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.Show less
2Linux
Oracle
2Linux
Linux Kernel
May 6, 2026
Jun 23, 2014
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service...Show more
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.Show less
6Canonical
LinuxOpensuse+3 more
9Enterprise Linux Server Aus
LinuxLinux Enterprise Desktop+6 more
Apr 21, 2026
Jun 7, 2014
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE comma...Show more
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
LinuxLinux Kernel+1 more
May 6, 2026
May 11, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause...Show more
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
LinuxLinux Kernel+1 more
May 6, 2026
May 11, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is suffic...Show more
The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows local users to cause a denial of service (integer underflow and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr and __skb_get_nlattr_nest functions before the vulnerability was announced.Show less