CVEs (48)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Linux OpensuseRedhat9Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+6 moreJun 17, 2026 May 7, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/ch...Show more |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Aus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS |
2Fedoraproject Redhat7389 Directory Server Enterprise Linux AusEnterprise Linux Desktop+4 moreNov 21, 2024 Sep 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service. |
6Canonical DebianF5+3 more27Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+24 moreNov 21, 2024 Jul 6, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writab...Show more |
3Debian MozillaRedhat7Debian Linux Enterprise Linux AusEnterprise Linux Desktop+4 moreNov 21, 2024 Jun 11, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2. |
4Canonical DebianMozilla+1 more8Debian Linux Enterprise Linux AusEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vu...Show more |
3Debian MozillaRedhat8Debian Linux Enterprise Linux AusEnterprise Linux Desktop+5 moreNov 25, 2025 Jun 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a pote...Show more |
2Mozilla Redhat6Enterprise Linux Aus Enterprise Linux DesktopEnterprise Linux Eus+3 moreNov 25, 2025 Jun 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API th...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Aus+8 moreNov 21, 2024 Feb 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes tha...Show more |
3Debian LinuxRedhat6Debian Linux Enterprise LinuxEnterprise Linux Aus+3 moreMay 13, 2026 Aug 19, 2017 N/A· v4 7.0 HIGH· v3 7.6 HIGH· v2 Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that le...Show more |
7Canonical DebianFedoraproject+4 more18Cloud Backup Debian LinuxEnterprise Linux+15 moreApr 21, 2026 Nov 10, 2016 N/A· v4 7.0 HIGH· v3 7.2 HIGH· v2 Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,...Show more |
7Canonical DebianFedoraproject+4 more19Debian Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism...Show more |
7Canonical DebianLinux+4 more19Debian Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sen...Show more |
2Linux Redhat7Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+4 moreApr 29, 2026 Mar 1, 2013 N/A· v4 N/A· v3 3.6 LOW· v2 kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call. |
5Canonical DebianMozilla+2 more12Debian Linux Enterprise Linux AusEnterprise Linux Desktop+9 moreApr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow re...Show more |
5Canonical DebianMozilla+2 more12Debian Linux Enterprise Linux AusEnterprise Linux Desktop+9 moreApr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey...Show more |
5Canonical DebianMozilla+2 more12Debian Linux Enterprise Linux AusEnterprise Linux Desktop+9 moreApr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMon...Show more |
5Canonical DebianMozilla+2 more12Debian Linux Enterprise Linux AusEnterprise Linux Desktop+9 moreApr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operatin...Show more |
5Canonical DebianMozilla+2 more12Debian Linux Enterprise Linux AusEnterprise Linux Desktop+9 moreApr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMo...Show more |
4Canonical MozillaOpensuse+1 more9Enterprise Linux Aus Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of...Show more |