CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more6Debian Linux Enterprise LinuxFedora+3 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing. |
6Canonical DebianNovell+3 more7Debian Linux Enterprise LinuxJdk+4 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. |
7Canonical DebianFedoraproject+4 more10Debian Linux Enterprise LinuxFedora+7 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.4 MEDIUM· v2 Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related...Show more |
6Canonical DebianNovell+3 more8Debian Linux Enterprise LinuxJdk+5 moreMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. |
2Jasper Project Redhat2Enterprise Linux JasperMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file. |
2Jasper Project Redhat2Enterprise Linux JasperMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profi...Show more |
4Bsd Mailx Project HeirloomOracle+1 more4Bsd Mailx Enterprise LinuxLinux+1 moreMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address. |
4Debian OpensuseRedhat+1 more5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreMay 6, 2026 Dec 1, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a de...Show more |
7Canonical DebianLinux+4 more10Debian Linux Enterprise LinuxEvergreen+7 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to ki...Show more |
7Canonical DebianLinux+4 more10Debian Linux Enterprise LinuxEnterprise Mrg+7 moreMay 6, 2026 Nov 10, 2014 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c...Show more |
7Canonical DebianLinux+4 more7Debian Linux Enterprise LinuxEvergreen+4 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. |
6Canonical DebianLinux+3 more6Debian Linux Enterprise LinuxEvergreen+3 moreMay 6, 2026 Nov 10, 2014 N/A· v4 5.5 MEDIUM· v3 4.7 MEDIUM· v2 arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafte...Show more |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreMay 6, 2026 Nov 10, 2014 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging inco...Show more |
5Apple CanonicalDebian+2 more5Debian Linux Enterprise LinuxLibxml2+2 moreMay 6, 2026 Nov 4, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a c...Show more |
4Canonical OpensuseRedhat+1 more4Enterprise Linux OpensuseRuby+1 moreMay 6, 2026 Nov 3, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Ex...Show more |
11Apple DebianFedoraproject+8 more20Aix DatabaseDebian Linux+17 moreMay 28, 2026 Oct 15, 2014 N/A· v4 3.4 LOW· v3 4.3 MEDIUM· v2 The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 25, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 24, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more |
2Fedoraproject Redhat3389 Directory Server Directory ServerEnterprise LinuxMay 6, 2026 Aug 21, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory. |
3Canonical RedhatSamba3Enterprise Linux SambaUbuntu LinuxMay 6, 2026 Aug 6, 2014 N/A· v4 N/A· v3 7.9 HIGH· v2 NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on...Show more |