Search

Found 1,996 results in 811ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2014-2402 high 7.5 ubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Librar…
CVE-2014-2397 critical 9.3 debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspo…
CVE-2014-0461 critical 9.3 debian debianubuntu ubuntu oracleibm 12y ago Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to…
CVE-2014-0460 medium 5.8 debian debianubuntu ubuntu oraclejuniper 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vecto…
CVE-2014-0459 medium 4.3 FIX debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect availability via unknown vectors related to 2D.
CVE-2014-0458 high 7.5 debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS,…
CVE-2014-0457 critical 10.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and avai…
CVE-2014-0456 critical 10.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to…
CVE-2014-0455 critical 9.3 ubuntu ubuntu oracleibm 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Librar…
CVE-2014-0454 high 7.5 ubuntu ubuntu oracleibm 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Securi…
CVE-2014-0453 medium 4.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unkno…
CVE-2014-0452 high 7.5 debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS,…
CVE-2014-0451 high 7.5 debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to…
CVE-2014-0446 high 7.5 debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors re…
CVE-2014-0429 critical 10.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availab…
CVE-2011-3628 medium 6.9 FIX ubuntu ubuntudebian debian canonical 12y ago Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ub…
CVE-2013-5704 medium 5.0 FIX debian debian rhelmacos macos apacheredhatoracle 12y ago The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfe…
CVE-2014-2523 critical 10.0 FIX debian debianubuntu ubuntu linux-kernel 12y ago net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which allows remote attackers to cause a denial of service (system crash) or possibl…
CVE-2014-2497 medium 4.3 FIX debian debianubuntu ubuntususe suse php 12y ago The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a c…
CVE-2014-1514 critical 9.8 9.8 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a …
CVE-2014-1513 high 8.8 8.8 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayB…
CVE-2014-1512 critical 10.0 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows r…
CVE-2014-1511 critical 9.8 10.0 EXP ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.
CVE-2014-1510 critical 9.8 10.0 EXP ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript cod…
CVE-2014-1509 high 8.8 8.8 ubuntu ubuntususe suse rhel mozillasuse 12y ago Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allow…
CVE-2014-1508 critical 9.1 9.1 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive…
CVE-2014-1505 high 7.5 7.5 ubuntu ubuntudebian debiansuse suse mozillanovell 12y ago The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement…
CVE-2014-1497 high 8.8 8.8 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain se…
CVE-2014-1493 critical 9.8 9.8 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to c…
CVE-2014-2241 medium 6.8 FIX debian debianubuntu ubuntu freetype 12y ago The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to c…
CVE-2014-0098 medium 5.0 FIX debian debianubuntu ubuntu apacheoracle 12y ago The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon cra…
CVE-2013-6438 medium 5.0 FIX debian debianubuntu ubuntu apacheoracle 12y ago The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote atta…
CVE-2014-2270 medium 4.3 FIX debian debianubuntu ubuntususe suse file_projectphp 12y ago softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE execu…
CVE-2013-6476 medium 4.4 FIX debian debianubuntu ubuntufedora fedora linuxfoundation 12y ago The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same…
CVE-2013-6475 medium 6.8 FIX debian debianubuntu ubuntufedora fedora linuxfoundation 12y ago Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a c…
CVE-2013-6474 medium 6.8 FIX debian debianubuntu ubuntufedora fedora linuxfoundation 12y ago Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
CVE-2013-6473 medium 6.8 FIX debian debianubuntu ubuntu linuxfoundation 12y ago Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.
CVE-2013-4496 medium 5.0 FIX ubuntu ubuntudebian debian samba 12y ago Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obta…
CVE-2014-0004 medium 6.9 FIX ubuntu ubuntudebian debian freedesktop 12y ago Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.
CVE-2014-0101 high 7.8 FIX debian debian rhelubuntu ubuntu f5 12y ago The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call,…
CVE-2014-1874 medium 4.9 FIX debian debiansuse suseubuntu ubuntu 12y ago The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_…
CVE-2014-1943 medium 5.0 FIX debian debianubuntu ubuntu fine_free_file_projectphp 13y ago Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.
CVE-2013-7327 medium 6.8 ubuntu ubuntu php 13y ago The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspeci…
CVE-2012-3406 medium 6.8 FIX debian debian rhelubuntu ubuntu gnuredhat 13y ago The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SP…
CVE-2012-3405 medium 5.0 FIX debian debian rhelubuntu ubuntu gnuredhat 13y ago The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to …
CVE-2012-3404 medium 5.0 FIX debian debian rhelubuntu ubuntu gnuredhat 13y ago The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to …
CVE-2013-6393 medium 6.8 FIX debian debiansuse suseubuntu ubuntu pyyamlredhat 13y ago Heap Based Buffer Overflow in libyaml
CVE-2013-2038 medium 4.3 FIX slesdebian debianubuntu ubuntu gpsd_project 13y ago The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpret…
CVE-2014-1491 medium 4.3 FIX debian debiansuse suseubuntu ubuntu mozillaoracle 13y ago Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does n…
CVE-2014-1490 critical 9.3 FIX suse susedebian debianubuntu ubuntu mozillaoracle 13y ago Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24…
CVE-2014-1489 medium 4.3 suse suseubuntu ubuntu mozilla 13y ago Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore…
CVE-2014-1488 critical 10.0 suse suseubuntu ubuntu mozilla 13y ago The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that ha…
CVE-2014-1487 high 7.5 7.5 suse suse rhelubuntu ubuntu mozillasuse 13y ago The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Polic…
CVE-2014-1486 critical 9.8 9.8 fedora fedorasuse suse rhel mozillasuse 13y ago Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers t…
CVE-2014-1485 high 7.5 suse suseubuntu ubuntu mozilla 13y ago The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directiv…
CVE-2014-1483 medium 5.0 suse suseubuntu ubuntu mozillasuse 13y ago Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain t…
CVE-2014-1482 high 8.8 8.8 suse suse rhelubuntu ubuntu mozillasuse 13y ago RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attacke…
CVE-2014-1481 high 7.5 7.5 suse suse rhelubuntu ubuntu mozillasuse 13y ago Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging in…
CVE-2014-1480 medium 4.3 suse suseubuntu ubuntu mozilla 13y ago The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjac…
CVE-2014-1479 high 7.5 7.5 suse suse rhelubuntu ubuntu mozillasuse 13y ago The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operatio…
CVE-2014-1478 critical 10.0 suse suseubuntu ubuntu mozilla 13y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and applicat…
CVE-2014-1477 critical 9.8 9.8 rhelubuntu ubuntudebian debian mozillasuse 13y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to c…
CVE-2011-4613 medium 5.6 EXPFIX ubuntu ubuntudebian debian x.org 13y ago The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restricti…
CVE-2011-3377 medium 4.3 FIX debian debiansuse suseubuntu ubuntu redhat 13y ago The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network conne…
CVE-2011-2725 medium 6.8 suse suseubuntu ubuntu kde 13y ago Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.
CVE-2013-0339 medium 6.8 FIX debian debianubuntu ubuntususe suse xmlsoft 13y ago libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote at…
CVE-2013-6425 medium 5.0 FIX debian debianubuntu ubuntususe suse pixman 13y ago Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) v…
CVE-2013-6424 medium 5.0 FIX debian debianubuntu ubuntususe suse pixman 13y ago Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
CVE-2014-0412 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unk…
CVE-2014-0402 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unk…
CVE-2014-0401 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unk…
CVE-2014-0386 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unk…
CVE-2013-5891 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related …
CVE-2013-6422 medium 4.0 FIX debian debianubuntu ubuntu haxx 13y ago The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fie…
CVE-2013-6391 medium 5.8 FIX debian debianubuntu ubuntu openstackredhat 13y ago The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to …
CVE-2012-6151 medium 5.3 EXPFIX debian debianmacos macosubuntu ubuntu net-snmp 13y ago Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, …
CVE-2013-6673 medium 5.9 5.9 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it e…
CVE-2013-6672 medium 4.3 linux-kernelfedora fedorasuse suse mozilla 13y ago Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.
CVE-2013-6671 critical 9.8 9.8 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary…
CVE-2013-5619 high 7.5 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-…
CVE-2013-5618 critical 9.8 9.8 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunder…
CVE-2013-5616 critical 9.8 9.8 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.2…
CVE-2013-5615 critical 9.8 9.8 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions o…
CVE-2013-5614 medium 4.3 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attacker…
CVE-2013-5613 critical 9.8 9.8 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows …
CVE-2013-5612 medium 4.3 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Orig…
CVE-2013-5611 medium 5.8 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing…
CVE-2013-5610 critical 10.0 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and applicat…
CVE-2013-5609 critical 9.8 9.8 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to c…
CVE-2013-6410 high 7.5 FIX ubuntu ubuntudebian debian wouter_verhelst 13y ago nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partia…
CVE-2013-6712 medium 5.0 macos macossuse suseubuntu ubuntu php 13y ago The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of servi…
CVE-2013-1058 medium 5.8 ubuntu ubuntu canonical 13y ago maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
CVE-2013-6858 medium 4.3 FIX debian debiansuse suseubuntu ubuntu openstack 13y ago Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" …
CVE-2013-4474 medium 6.0 EXPFIX ubuntu ubuntudebian debian freedesktop 13y ago Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in …
CVE-2013-4473 high 7.5 FIX ubuntu ubuntudebian debian freedesktop 13y ago Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c…
CVE-2010-3443 medium 5.0 FIX ubuntu ubuntudebian debian quassel-irc 13y ago ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIV…
CVE-2013-4588 high 7.0 7.0 FIX ubuntu ubuntu linux-kerneldebian debian 13y ago Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_AD…
CVE-2013-4563 high 7.1 FIX ubuntu ubuntudebian debian linux-kernel 13y ago The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before …
CVE-2013-6629 medium 5.0 FIX slesdebian debianfedora fedora googleartifexlibjpeg-turbo 13y ago The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain dup…
CVE-2013-1057 medium 4.4 ubuntu ubuntu canonical 13y ago Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current wo…