CVEs (555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian MariadbOpensuse Project+3 more12Debian Linux Linux Enterprise DesktopLinux Enterprise Server+9 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors relat...Show more |
3Mariadb OracleSuse6Linux Enterprise Desktop Linux Enterprise ServerLinux Enterprise Software Development Kit+3 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 2.8 LOW· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED. |
4Mozilla OpensuseOpensuse Project+1 more4Firefox OpensuseOpensuse+1 moreMay 6, 2026 Jun 11, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rat...Show more |
3Gnome OpensuseOracle3Gnome Terminal OpensuseSolarisMay 6, 2026 May 21, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demons...Show more |
6Canonical FedoraprojectMozilla+3 more7Fedora FirefoxOpensuse+4 moreMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds w...Show more |
3Fedoraproject MozillaOracle3Fedora FirefoxSolarisMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it o...Show more |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 2.8 LOW· v2 Unspecified vulnerability Oracle the MySQL Server component 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Federated. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect availability via unknown vectors related to Options. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect availability via unknown vectors related to Performance Schema. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition. |
5Apache AppleCanonical+2 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreMay 6, 2026 Apr 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the...Show more |
6Canonical DebianOracle+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Mar 21, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in...Show more |
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted applicatio...Show more |
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (applic...Show more |
4Mozilla OpensuseOracle+1 more7Firefox Linux Enterprise DesktopLinux Enterprise Sdk+4 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scriptin...Show more |
5Mozilla OpensuseOpensuse Project+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a...Show more |
3Mozilla OracleSuse5Firefox Linux Enterprise DesktopLinux Enterprise Server+2 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection. |
5Mozilla OpensuseOpensuse Project+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution...Show more |