CVEs (474)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Mozilla OpensuseOpensuse Project+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generat...Show more |
5Mozilla OpensuseOpensuse Project+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash)...Show more |
5Mozilla OpensuseOpensuse Project+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreMay 6, 2026 Mar 19, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibl...Show more |
3Linux OpensuseSuse3Linux Enterprise Server Linux KernelOpensuseMay 6, 2026 Mar 11, 2014 N/A· v4 N/A· v3 6.1 MEDIUM· v2 The ip6_route_add function in net/ipv6/route.c in the Linux kernel through 3.13.6 does not properly count the addition of routes, which allows remote attackers to cause a denial of service (memory consumption) via a floo...Show more |
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to s...Show more |
3Linux RedhatSuse9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 7.2 HIGH· v2 The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux Enterprise Manager Ops CenterFedora+10 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux Enterprise Manager Ops CenterFedora+10 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products,...Show more |
6Canonical MozillaOpensuse+3 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web s...Show more |
5Canonical MozillaOpensuse+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-t...Show more |
5Canonical MozillaOpensuse+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow...Show more |
5Mozilla OpensuseOpensuse Project+2 more7Firefox Linux Enterprise DesktopLinux Enterprise Server+4 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application. |
5Canonical MozillaOpensuse+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements in...Show more |
5Canonical MozillaOpensuse+2 more8Firefox Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and tri...Show more |
4Canonical DebianSuse+1 more4Debian Linux Libxml2Linux Enterprise Server+1 moreApr 29, 2026 Jan 21, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a de...Show more |
2Gnu Suse3Glibc Linux Enterprise DebuginfoLinux Enterprise ServerApr 29, 2026 Dec 12, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostnam...Show more |
5Canonical FedoraprojectMozilla+2 more9Fedora FirefoxLinux Enterprise Desktop+6 moreApr 29, 2026 Dec 11, 2013 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-...Show more |
6Canonical FedoraprojectMozilla+3 more9Fedora FirefoxLinux Enterprise Desktop+6 moreApr 29, 2026 Dec 11, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations. |
6Canonical FedoraprojectMozilla+3 more9Fedora FirefoxLinux Enterprise Desktop+6 moreApr 29, 2026 Dec 11, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array acces...Show more |
7Canonical FedoraprojectMozilla+4 more16Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+13 moreApr 29, 2026 Dec 11, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended...Show more |