CVEs (129)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical FedoraprojectMozilla+3 more16Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+13 moreApr 29, 2026 Dec 11, 2013 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attac...Show more |
5Canonical FedoraprojectMozilla+2 more9Fedora FirefoxOpensuse+6 moreApr 29, 2026 Dec 11, 2013 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of G...Show more |
6Canonical FedoraprojectMozilla+3 more16Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+13 moreApr 29, 2026 Dec 11, 2013 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to e...Show more |
6Canonical FedoraprojectMozilla+3 more16Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+13 moreApr 29, 2026 Dec 11, 2013 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of serv...Show more |
2Linux Suse2Linux Kernel Suse Linux Enterprise ServerApr 29, 2026 Jun 8, 2013 N/A· v4 N/A· v3 3.3 LOW· v2 The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication...Show more |
5Canonical MozillaOpensuse+2 more14Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+11 moreApr 29, 2026 Nov 21, 2012 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to...Show more |
4Apple GoogleOpensuse+1 more7Chrome Iphone OsLinux Enterprise Server+4 moreApr 29, 2026 Feb 16, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncati...Show more |
3Linux RedhatSuse6Enterprise Linux Server Enterprise Linux WorkstationLinux Kernel+3 moreApr 29, 2026 Dec 23, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on t...Show more |
10Apache AppleDebian+7 more17Chrome Debian LinuxEnterprise Linux Desktop+14 moreApr 29, 2026 Dec 7, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impac...Show more |
9Apache AppleCanonical+6 more15Chrome Debian LinuxEnterprise Linux Desktop+12 moreApr 29, 2026 Nov 17, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows con...Show more |
3Canonical LinuxSuse5Linux Enterprise High Availability Extension Linux KernelSuse Linux Enterprise Desktop+2 moreApr 29, 2026 Sep 30, 2010 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies th...Show more |
3Linux SuseVmware4Esx Linux KernelSuse Linux Enterprise Desktop+1 moreApr 29, 2026 Sep 24, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer...Show more |
5Canonical LinuxOpensuse+2 more6Esx Linux KernelOpensuse+3 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information f...Show more |
6Avaya CanonicalLinux+3 more13Aura Communication Manager Aura Presence ServicesAura Session Manager+10 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to o...Show more |
3Canonical LinuxSuse4Linux Kernel Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL p...Show more |
7Avaya CanonicalDebian+4 more15Aura Communication Manager Aura Presence ServicesAura Session Manager+12 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more |
4Canonical LinuxSuse+1 more5Esx Linux KernelSuse Linux Enterprise Desktop+2 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace h...Show more |
3Canonical LinuxSuse5Linux Kernel Suse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+2 moreApr 29, 2026 Sep 8, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a...Show more |
4Canonical LinuxSuse+1 more6Esx Linux Enterprise High Availability ExtensionLinux Kernel+3 moreApr 29, 2026 Sep 8, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor. |
3Google OpensuseSuse4Chrome OpensuseSuse Linux Enterprise Desktop+1 moreApr 29, 2026 Jun 15, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remot...Show more |