CVEs (461)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian MozillaOpensuse+1 more8Debian Linux FirefoxLinux Enterprise Desktop+5 moreApr 29, 2026 Feb 1, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
5Canonical DebianMozilla+2 more9Debian Linux FirefoxLinux Enterprise Desktop+6 moreApr 29, 2026 Feb 1, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a...Show more |
4Debian MozillaOpensuse+1 more8Debian Linux FirefoxLinux Enterprise Desktop+5 moreApr 29, 2026 Feb 1, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a d...Show more |
3Mozilla OpensuseSuse7Firefox Linux Enterprise DesktopLinux Enterprise Server+4 moreApr 29, 2026 Feb 1, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vector...Show more |
8Debian FedoraprojectFreebsd+5 more10Debian Linux FedoraFreebsd+7 moreApr 29, 2026 Dec 25, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products a...Show more |
7Canonical DebianFedoraproject+4 more9Debian Linux Enterprise Linux DesktopFedora+6 moreApr 29, 2026 Dec 15, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute a...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraJasper+5 moreApr 29, 2026 Dec 15, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted...Show more |
2Apple Suse4Iphone Os Linux Enterprise DesktopLinux Enterprise Server+1 moreApr 29, 2026 Nov 11, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document. |
The modify_resolvconf_suse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to execute arbitrary commands via a crafted DNS domain name. |
5Debian FedoraprojectMit+2 more7Debian Linux FedoraKrb5 Appl+4 moreApr 29, 2026 Jul 11, 2011 N/A· v4 N/A· v3 6.5 MEDIUM· v2 ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group acc...Show more |
4Adobe GoogleOpensuse+1 more7Acrobat Acrobat ReaderAdobe Air+4 moreApr 21, 2026 Apr 13, 2011 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4....Show more |
3Linux RedhatSuse6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 29, 2026 Apr 4, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted applica...Show more |
3Linux OpensuseSuse5Linux Enterprise Desktop Linux Enterprise ServerLinux Enterprise Software Development Kit+2 moreApr 29, 2026 Jan 7, 2011 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service (system crash) via malformed X.25 (1) X...Show more |
3Linux OpensuseSuse5Linux Enterprise Desktop Linux Enterprise Real Time ExtensionLinux Enterprise Server+2 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device. |
4Fedoraproject LinuxOpensuse+1 more7Fedora Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 4.7 MEDIUM· v2 Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device. |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 1.9 LOW· v2 net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by levera...Show more |
4Fedoraproject LinuxOpensuse+1 more7Fedora Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 6.2 MEDIUM· v2 The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel...Show more |
4Fedoraproject LinuxOpensuse+1 more7Fedora Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instructi...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet...Show more |