CVEs (555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianMozilla+2 more9Debian Linux FirefoxFirefox Esr+6 moreMay 6, 2026 Jul 6, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of servic...Show more |
3Mozilla NovellOracle6Firefox Firefox EsrSolaris+3 moreMay 6, 2026 Jul 6, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors...Show more |
5Canonical DebianMozilla+2 more8Debian Linux Network Security ServicesSolaris+5 moreMay 6, 2026 Jul 6, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine sta...Show more |
4Oracle RedhatRuby Lang+1 more4Enterprise Linux RubyRubygems+1 moreMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains v...Show more |
5Apple HpOracle+2 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+9 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU...Show more |
4Apple OraclePhp+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of se...Show more |
4Apple OraclePhp+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted len...Show more |
3Hp LighttpdOracle3Lighttpd SolarisVirtual Customer Access SystemMay 6, 2026 Jun 9, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line char...Show more |
5Debian FedoraprojectLinux+2 more6Debian Linux Enterprise MrgFedora+3 moreMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit settin...Show more |
The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as...Show more |
2Oracle Wireshark3Linux SolarisWiresharkMay 6, 2026 May 26, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a denial of service...Show more |
2Oracle Wireshark3Linux SolarisWiresharkMay 6, 2026 May 26, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (a...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavo...Show more |
3Fedoraproject OracleSquid Cache4Fedora LinuxSolaris+1 moreMay 6, 2026 May 18, 2015 N/A· v4 N/A· v3 2.6 LOW· v2 Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which...Show more |
4Mozilla NovellOpensuse+1 more8Firefox Firefox EsrOpensuse+5 moreMay 6, 2026 May 14, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML...Show more |
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend i...Show more |
The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds...Show more |
8Apple CanonicalDebian+5 more9Curl Debian LinuxFedora+6 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly hav...Show more |
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability via vectors related to Kernel IDMap. |
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Accounting commands. |