CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Opensuse Redhat4Enterprise Linux Enterprise VirtualizationLibvirt+1 moreMay 6, 2026 Aug 3, 2014 N/A· v4 N/A· v3 1.2 LOW· v2 libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction wi...Show more |
2Opensuse Redhat4Enterprise Linux Enterprise VirtualizationLibvirt+1 moreMay 6, 2026 Aug 3, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity refere...Show more |
3Debian OracleRedhat5Debian Linux Enterprise LinuxJdk+2 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a d...Show more |
5Canonical F5Linux+2 more26Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+23 moreMay 6, 2026 Jun 23, 2014 N/A· v4 N/A· v3 2.3 LOW· v2 The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from r...Show more |
A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote attackers to cause a denial of service (CPU consumption) via a crafted request. NOTE: this vulnerability exists because of...Show more |
2Fedoraproject Redhat2Enterprise Linux SssdMay 6, 2026 Jun 11, 2014 N/A· v4 N/A· v3 3.3 LOW· v2 The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified...Show more |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of s...Show more |
9Fedoraproject Filezilla ProjectMariadb+6 more16Application Processing Engine Firmware Cp1543 1 FirmwareEnterprise Linux+13 moreMay 6, 2026 Jun 5, 2014 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS he...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations,...Show more |
3Linux RedhatSuse4Enterprise Linux Enterprise MrgLinux Enterprise Desktop+1 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 3.3 LOW· v2 kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a deni...Show more |
7Canonical DebianF5+4 more30Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+27 moreApr 21, 2026 May 7, 2014 N/A· v4 5.5 MEDIUM· v3 6.9 MEDIUM· v2 The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory co...Show more |
Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table update request, which triggers a heap-bas...Show more |
3Qemu RedhatXen3Enterprise Linux QemuXenMay 6, 2026 Apr 1, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted S...Show more |
Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vu...Show more |
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT du...Show more |
The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which...Show more |
2Qemu Redhat3Enterprise Linux Enterprise Linux Server SupplementaryQemuApr 29, 2026 Feb 26, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute ar...Show more |
4Opensuse Opensuse ProjectRedhat+1 more6Cloudforms Enterprise LinuxOpensuse+3 moreApr 29, 2026 Feb 20, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject...Show more |
3Canonical GnuRedhat4Enterprise Linux Enterprise VirtualizationGlibc+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allo...Show more |