Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Debian Linux MEDIUM 5.0
CVE-2014-9323

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer…

Fix: 2.1.7+
Fix from $1,600 2014-12-16
Linux Kernel HIGH 7.8
CVE-2014-7826

kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem,…

Fix: 3.2.65 / 3.4.106+
Fix from $1,950 2014-11-10
HTTP Server MEDIUM 5.0
CVE-2014-3581EPSS 14%

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote atta…

Patch available
Fix from $1,600 2014-10-10
Debian Linux HIGH 7.8
CVE-2014-4344EPSS 7%

The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 a…

Patch available
Fix from $1,950 2014-08-14
Linux Kernel HIGH 7.1
CVE-2014-5077EPSS 6%

The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attacke…

Fix: 3.2.63 / 3.4.103+
Fix from $1,950 2014-08-01
Virtualization MEDIUM 5.0
CVE-2014-3469

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of ser…

Patch available
Fix from $1,600 2014-06-05
Linux Kernel HIGH 7.8
CVE-2014-0101EPSS 7%

The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable …

Fix: 3.2.56 / 3.4.84+
Fix from $1,950 2014-03-11
Codesys Runtime Toolkit MEDIUM 5.0
CVE-2014-0757

Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference …

Fix: after 2.4.7.43
Fix from $1,600 2014-01-31
Libpng MEDIUM 6.5
CVE-2013-6954

The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and applicat…

Fix: after 1.6.8
Fix from $1,600 2014-01-12
Enterprise Linux Desktop MEDIUM 5.5
CVE-2011-2519

Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (inva…

Fix: 3.3.0+
Fix from $1,600 2013-12-27
Modsecurity MEDIUM 5.0
CVE-2013-2765EPSS 14%

The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, proces…

Fix: 2.7.4+
Fix from $1,600 2013-07-15
Linux Kernel HIGH 7.8
CVE-2013-1059

net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash…

Fix: 3.0.86 / 3.2.49+
Fix from $1,950 2013-07-08
Linux Kernel HIGH 7.5
CVE-2011-2482

A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as used in Red Hat Enterprise Linux…

Fix: 2.6.21+
Fix from $1,950 2013-06-08
Kerberos 5 MEDIUM 5.0
CVE-2013-1415

The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC…

Fix: 1.10.4+
Fix from $1,600 2013-03-05
Kerberos 5 MEDIUM 5.0
CVE-2012-1016

The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in …

Fix: 1.10.4+
Fix from $1,600 2013-03-05
Enterprise Linux Desktop HIGH 9.3
CVE-2012-2039

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux;…

Fix: after 11.2.202.235
Fix from $1,950 2012-06-09
Linux Kernel MEDIUM 5.5
CVE-2011-4081

crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly…

Fix: 3.1+
Fix from $1,600 2012-05-24
Linux Kernel HIGH 7.8
CVE-2012-1097

The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows l…

Fix: 3.0.24 / 3.2.10+
Fix from $1,950 2012-05-17
Linux Kernel MEDIUM 5.5
CVE-2012-1146

The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are…

Fix: 3.2.10+
Fix from $1,600 2012-05-17
Linux Kernel MEDIUM 5.5
CVE-2011-4594

The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted …

Fix: 3.1+
Fix from $1,600 2012-05-17
Linux Kernel MEDIUM 5.5
CVE-2011-3637

The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that t…

Fix: 2.6.39+
Fix from $1,600 2012-05-17
Linux Kernel HIGH 7.8
CVE-2011-2525

The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin …

Fix: 2.6.35+
Fix from $1,950 2012-02-02
Linux Kernel MEDIUM 5.7
CVE-2011-1478

The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset th…

Fix: 2.6.38+
Fix from $1,600 2011-10-23
Windows 2003 Server HIGH 7.1
CVE-2011-1985

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a…

Mitigation only
Fix from $1,950 2011-10-12
Linux Kernel HIGH 7.8
CVE-2011-1771

The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference…

Fix: 2.6.39+
Fix from $1,950 2011-09-06
Linux Kernel HIGH 7.2
CVE-2011-2184

The key_replace_session_keyring function in security/keys/process_keys.c in the Linux kernel before 2.6.39.1 does not initialize a certain structure …

Fix: 2.6.39.1+
Fix from $1,950 2011-09-06
Linux Kernel HIGH 7.8
CVE-2011-1093

The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before …

Fix: 2.6.38+
Fix from $1,950 2011-07-18
Fedora MEDIUM 6.5
CVE-2011-2691

The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function ca…

Fix: 1.0.55 / 1.2.45+
Fix from $1,600 2011-07-17
Windows 2003 Server HIGH 8.4
CVE-2011-1881

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Go…

Mitigation only
Fix from $1,950 2011-07-13
Windows 2003 Server HIGH 8.4
CVE-2011-1282

The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista S…

Mitigation only
Fix from $1,950 2011-07-13