Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2017-12873

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impact…

Fix: after 1.14.10
Fix from $2,300 2017-09-01
Debian Linux CRITICAL 9.8
CVE-2017-0899EPSS 10%

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem…

Fix: after 2.6.12
Fix from $2,300 2017-08-31
Debian Linux CRITICAL 9.8
CVE-2017-14062

Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possib…

Fix: 2.0.4+
Fix from $2,300 2017-08-31
Debian Linux CRITICAL 9.8
CVE-2017-12865EPSS 6%

Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbit…

Fix: after 1.34
Fix from $2,300 2017-08-29
Xbindkeys Config CRITICAL 9.8
CVE-2014-9513

Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2017-08-28
Debian Linux CRITICAL 9.8
CVE-2017-13139

In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.

Fix: after 6.9.9-0
Fix from $2,300 2017-08-23
Debian Linux CRITICAL 9.6
CVE-2017-10096

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u…

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10101

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u…

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10107

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u1…

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10110

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u13…

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10111

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java …

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.0
CVE-2017-10102

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u1…

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10086

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. E…

Fix: after 11.70.1
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10087

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10089

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE: 6u151, 7u141 and …

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10090

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…

Patch available
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.8
CVE-2015-7871EPSS 82%

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Fix: 4.2.8 / 4.3.77+
Fix from $2,300 2017-08-07
Debian Linux CRITICAL 9.8
CVE-2017-12562

Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of…

Patch available
Fix from $2,300 2017-08-05
Debian Linux CRITICAL 9.8
CVE-2017-12424

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may l…

Fix: 4.5+
Fix from $2,300 2017-08-04
Debian Linux CRITICAL 9.8
CVE-2017-11139

GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.

Patch available
Fix from $2,300 2017-07-10
Debian Linux CRITICAL 9.8
CVE-2016-4000EPSS 6%

Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

Patch available
Fix from $2,300 2017-07-06
Debian Linux CRITICAL 9.8
CVE-2017-7494 KEVEPSS 99%

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to up…

Fix: 4.4.0 / 4.4.14+
Fix from $2,300 2017-05-30
Debian Linux CRITICAL 9.8
CVE-2017-9214

In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsi…

Patch available
Fix from $2,300 2017-05-23
Debian Linux CRITICAL 9.8
CVE-2016-9841EPSS 8%

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Fix: after 8.0.12
Fix from $2,300 2017-05-23
Debian Linux CRITICAL 9.8
CVE-2016-9843EPSS 6%

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian C…

Fix: after 8.0.12
Fix from $2,300 2017-05-23
Debian Linux CRITICAL 9.8
CVE-2017-2518EPSS 5%

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Debian Linux CRITICAL 9.8
CVE-2017-2519

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Debian Linux CRITICAL 9.8
CVE-2017-2520

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Debian Linux CRITICAL 9.8
CVE-2016-10243EPSS 6%

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

Patch available
Fix from $2,300 2017-05-02
Dpkg CRITICAL 9.8
CVE-2017-8283

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hu…

Patch available
Fix from $2,300 2017-04-26