Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Subversion MEDIUM 5.0
CVE-2011-1752EPSS 8%

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of se…

Fix: 1.6.17 / 10.7.3+
Fix from $1,600 2011-06-06
.net Framework HIGH 7.7
CVE-2011-1271EPSS 20%

The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle express…

No fix yet
Fix from $1,950 2011-05-10
Chrome MEDIUM 5.0
CVE-2011-1691

The counterToCSSValue function in CSSComputedStyleDeclaration.cpp in the Cascading Style Sheets (CSS) implementation in WebCore in WebKit before r822…

Fix: 11.0.696.43+
Fix from $1,600 2011-04-15
Windows 2003 Server HIGH 7.2
CVE-2011-1229

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Go…

Patch available
Fix from $1,950 2011-04-13
Windows 2003 Server HIGH 8.4
CVE-2011-1231

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Go…

Mitigation only
Fix from $1,950 2011-04-13
Windows 2003 Server HIGH 7.8
CVE-2011-0676

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Go…

Mitigation only
Fix from $1,950 2011-04-13
Linux Kernel HIGH 7.5
CVE-2011-0709

The br_mdb_ip_get function in net/bridge/br_multicast.c in the Linux kernel before 2.6.35-rc5 allows remote attackers to cause a denial of service (N…

Fix: after 2.6.34.7
Fix from $1,950 2011-02-18
Linux Kernel HIGH 7.9
CVE-2010-4263

The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when …

Fix: 2.6.34+
Fix from $1,950 2011-01-18
Linux Kernel HIGH 7.1
CVE-2010-4342

The aun_incoming function in net/econet/af_econet.c in the Linux kernel before 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause a…

Fix: 2.6.37+
Fix from $1,950 2010-12-30
Chrome Os MEDIUM 5.0
CVE-2010-4576

browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain …

Fix: 8.0.552.224 / 8.0.552.343+
Fix from $1,600 2010-12-22
Fedora HIGH 7.5
CVE-2010-3702

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and pos…

Fix: after 1.3.11
Fix from $1,950 2010-11-05
Linux Kernel MEDIUM 6.6
CVE-2010-3437

Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users …

Fix: 2.6.36+
Fix from $1,600 2010-10-04
Linux Kernel MEDIUM 5.5
CVE-2010-3079

kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and…

Fix: 2.6.35.5+
Fix from $1,600 2010-09-30
Linux Kernel HIGH 7.8
CVE-2010-2960

The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyrin…

Fix: 2.6.35.4+
Fix from $1,950 2010-09-08
Linux Kernel HIGH 10.0
CVE-2010-2495

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain …

Fix: 2.6.34+
Fix from $1,950 2010-09-08
Linux Kernel HIGH 7.8
CVE-2010-2798

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with s…

Fix: 2.6.35+
Fix from $1,950 2010-09-08
Debian Linux MEDIUM 6.8
CVE-2010-1321EPSS 7%

The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as u…

Fix: 1.8.2+
Fix from $1,600 2010-05-19
Fedora MEDIUM 5.0
CVE-2010-0751

The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a de…

Fix: 1.24+
Fix from $1,600 2010-04-06
Linux Kernel HIGH 7.1
CVE-2010-0006

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers t…

Fix: 2.6.32.4+
Fix from $1,950 2010-01-26
Linux Kernel HIGH 7.0
CVE-2009-3547

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference …

Fix: after 2.6.31.14
Fix from $1,950 2009-11-04
Linux Kernel HIGH 7.8
CVE-2009-3620

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initializat…

Fix: 2.6.31.1+
Fix from $1,950 2009-10-22
Linux Kernel HIGH 7.8
CVE-2009-2698EPSS 7%

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users …

Fix: 2.6.19+
Fix from $1,950 2009-08-27
Linux Kernel HIGH 7.8
CVE-2009-2768

The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 allows local users to cause a d…

Fix: 2.6.31+
Fix from $1,950 2009-08-14
OpenSSL MEDIUM 5.0
CVE-2009-1386EPSS 80%

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Cha…

Fix: 0.9.8i+
Fix from $1,600 2009-06-04
OpenSSL MEDIUM 5.0
CVE-2009-1387EPSS 10%

The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (N…

Fix: 0.9.8m+
Fix from $1,600 2009-06-04
Fedora MEDIUM 5.0
CVE-2009-1902EPSS 14%

The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost reques…

Fix: 2.5.9+
Fix from $1,600 2009-06-03
Debian Linux HIGH 7.5
CVE-2008-5183EPSS 9%

cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large numb…

Fix: 10.5.6+
Fix from $1,950 2008-11-21
Skulltag HIGH 7.5
CVE-2008-3597

Skulltag before 0.97d2-RC6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by sending a "command 29"…

Fix: 0.97d2+
Fix from $1,950 2008-08-12
Linux Kernel HIGH 7.8
CVE-2008-2812

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or p…

Fix: 2.6.25.10+
Fix from $1,950 2008-07-09
Exchange Server HIGH 7.8
CVE-2007-0039EPSS 45%

The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attacke…

Patch available
Fix from $1,950 2007-05-08