CVEs (461)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 25, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 24, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more |
4Canonical LinuxRedhat+1 more8Enterprise Linux Eus Enterprise Linux Server AusEnterprise Linux Server Tus+5 moreMay 6, 2026 Aug 1, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by...Show more |
5Debian LinuxOpensuse+2 more6Debian Linux Enterprise Linux Server AusLinux Enterprise Desktop+3 moreMay 6, 2026 Jul 19, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket. |
4Debian MariadbOracle+1 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Server+5 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR. |
6Debian MariadbOpensuse Project+3 more12Debian Linux Linux Enterprise DesktopLinux Enterprise Server+9 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors relat...Show more |
3Mariadb OracleSuse6Linux Enterprise Desktop Linux Enterprise ServerLinux Enterprise Software Development Kit+3 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 2.8 LOW· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED. |
2Oracle Suse3Linux Enterprise Desktop Linux Enterprise ServerMysqlMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 3.3 LOW· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP. |
4Debian MariadbOracle+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Server+4 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR. |
4Debian MariadbOracle+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Server+4 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC. |
2Oracle Suse3Linux Enterprise Desktop Linux Enterprise ServerMysqlMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRFTS. |
4Canonical DebianLinux+1 more6Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+3 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) vi...Show more |
5Canonical F5Linux+2 more26Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+23 moreMay 6, 2026 Jun 23, 2014 N/A· v4 N/A· v3 2.3 LOW· v2 The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from r...Show more |
3Directfb OpensuseSuse6Directfb Linux Enterprise DesktopLinux Enterprise Software Development Kit+3 moreMay 6, 2026 Jun 11, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, w...Show more |
3Directfb OpensuseSuse6Directfb Linux Enterprise DesktopLinux Enterprise Software Development Kit+3 moreMay 6, 2026 Jun 11, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbi...Show more |
6Canonical LinuxOpensuse+3 more9Enterprise Linux Server Aus LinuxLinux Enterprise Desktop+6 moreApr 21, 2026 Jun 7, 2014 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE comma...Show more |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of s...Show more |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS he...Show more |
4Debian GnuRedhat+1 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue...Show more |
5Debian F5Gnu+2 more15Arx Firmware Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN....Show more |