VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18467CVEs
CVE-2014-0576
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0581, CVE-2014-8440, and CVE-2014-8441.
Published 2014-11-11 · Modified
10.0EPSS 0.036
CVE-2014-0581
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-8440, and CVE-2014-8441.
Published 2014-11-11 · Modified
10.0EPSS 0.036
CVE-2026-76197
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-08-25 · Analyzed
10.0EPSS 0.035
CVE-2026-76195
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-08-25 · Analyzed
10.0EPSS 0.035
CVE-2010-3038
Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, which makes it easier for remote attackers to obtain access via the (a) FTP or (b) SSH daemon, aka Bug ID CSCti54008.
Published 2010-11-22 · Modified
10.0EPSS 0.033
CVE-2008-3496
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
Published 2008-08-06 · Modified
10.0EPSS 0.033
CVE-2019-14678
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Published 2019-11-14 · Modified
10.0EPSS 0.030
CVE-2010-2495
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.
Published 2010-09-08 · Modified
10.0EPSS 0.029
CVE-2018-5703
The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via vectors involving TLS.
Published 2018-01-16 · Modified
10.0EPSS 0.026
CVE-2019-15292
An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.
Published 2019-08-21 · Modified
10.0EPSS 0.026
CVE-2015-8104
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
Published 2015-11-16 · Modified
10.0EPSS 0.025
CVE-2005-3059
Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding."
Published 2005-09-26 · Modified
10.0EPSS 0.022
CVE-2007-3794
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.
Published 2007-07-15 · Modified
10.0EPSS 0.022
CVE-2012-4145
Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue."
Published 2012-08-06 · Modified
10.0EPSS 0.022
CVE-2021-39065
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system. IBM X-Force ID: 214958.
Published 2021-12-13 · Modified
10.0EPSS 0.022
CVE-2007-6047
Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.
Published 2007-11-20 · Modified
10.0EPSS 0.020
CVE-2007-6045
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
Published 2007-11-20 · Modified
10.0EPSS 0.018
CVE-2011-3101
Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unspecified flaw in an NVIDIA driver, which has unknown impact and attack vectors. NOTE: see CVE-2012-3105 for the related MFSA 2012-34 issue in Mozilla products.
Published 2012-05-16 · Modified
10.0EPSS 0.018
CVE-2007-6048
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
Published 2007-11-20 · Modified
10.0EPSS 0.018
CVE-2010-2298
browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0.375.70 on Linux does not properly handle ViewHostMsg_DatabaseOpenFile messages in chroot-based sandboxing, which allows remote attackers to bypass intended sandbox restrictions via vectors involving fchdir and chdir calls.
Published 2010-06-15 · Modified
10.0EPSS 0.016
CVE-2010-0121
The cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, Mac RealPlayer 11.0 through 12.0.0.1444, and Linux RealPlayer 11.0.2.1744 does not properly perform initialization, which has unspecified impact and attack vectors.
Published 2010-12-14 · Modified
10.0EPSS 0.016
CVE-2007-6051
IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
Published 2007-11-20 · Modified
10.0EPSS 0.015
CVE-2026-48323
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Published 2026-08-03 · Analyzed
10.0EPSS 0.014
CVE-2026-76193
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-08-25 · Analyzed
10.0EPSS 0.013
CVE-2026-75721
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-75703
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-75699
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-73369
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-89275
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-84412
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-75723
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-09-22 · Analyzed
10.0EPSS 0.012
CVE-2026-48449
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-07-30 · Analyzed
10.0EPSS 0.012
CVE-2026-48303
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-06-09 · Analyzed
10.0EPSS 0.012
CVE-2026-48286
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-06-30 · Analyzed
10.0EPSS 0.012
CVE-2025-9588
OS Command Injection in Iron Mountain's enVision
Published 2025-09-23 · Modified
10.0EPSS 0.011
CVE-2026-48330
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-08-03 · Analyzed
10.0EPSS 0.010
CVE-2026-48331
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-08-03 · Analyzed
10.0EPSS 0.009
CVE-2026-47938
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-06-09 · Analyzed
10.0EPSS 0.009
CVE-2024-38558
net: openvswitch: fix overwriting ct original tuple for ICMPv6
Published 2024-06-19 · Modified
10.0EPSS 0.008
CVE-2025-30411
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Published 2026-02-20 · Analyzed
10.0EPSS 0.008
← Prev13 / 462Next →