Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.1
CVE-2016-5116

gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers …

Fix: after 2.2.1
Fix from $2,300 2016-08-07
Debian Linux CRITICAL 9.8
CVE-2016-0749EPSS 8%

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $2,300 2016-06-09
Debian Linux CRITICAL 9.8
CVE-2016-5108EPSS 22%

Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause …

Fix: after 2.2.3
Fix from $2,300 2016-06-08
Debian Linux CRITICAL 9.8
CVE-2015-7695

The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL c…

Fix: after 1.12.15
Fix from $2,300 2016-06-07
Debian Linux CRITICAL 9.8
CVE-2014-9746

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in t…

Fix: after 2.5.3
Fix from $2,300 2016-06-07
Debian Linux CRITICAL 9.8
CVE-2016-4024

Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which…

Fix: after 1.4.8
Fix from $2,300 2016-05-13
Debian Linux CRITICAL 9.8
CVE-2016-2195EPSS 6%

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possib…

Fix: after 1.10.10
Fix from $2,300 2016-05-13
Debian Linux CRITICAL 9.8
CVE-2016-4422

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux CRITICAL 9.8
CVE-2015-0857

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux CRITICAL 9.8
CVE-2016-3074EPSS 37%

Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potential…

Fix: 5.5.35 / 5.6.21+
Fix from $2,300 2016-04-26
Debian Linux CRITICAL 9.8
CVE-2016-1659

Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 49.0.2623.112
Fix from $2,300 2016-04-18
Debian Linux CRITICAL 9.8
CVE-2016-2054EPSS 5%

Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary cod…

Patch available
Fix from $2,300 2016-04-13
Debian Linux CRITICAL 9.8
CVE-2015-8710

The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds h…

Fix: 2.9.3+
Fix from $2,300 2016-04-11
Debian Linux CRITICAL 9.8
CVE-2016-2385EPSS 27%

Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows r…

Fix: after 4.3.4
Fix from $2,300 2016-04-11
Debian Linux CRITICAL 9.8
CVE-2016-3153

SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related …

Patch available
Fix from $2,300 2016-04-08
Debian Linux CRITICAL 9.8
CVE-2016-2851EPSS 21%

Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and ap…

Fix: after 4.1.0
Fix from $2,300 2016-04-07
Debian Linux CRITICAL 9.8
CVE-2014-2323EPSS 62%

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host nam…

Fix: 1.4.35+
Fix from $2,300 2014-03-14
Debian Linux CRITICAL 9.1
CVE-2012-2239

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity…

Fix: 1.4.4 / 1.5.3+
Fix from $2,300 2012-11-24
Debian Linux CRITICAL 9.8
CVE-2012-0507 KEVEPSS 98%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 …

Mitigation only
Fix from $2,300 2012-06-07
Debian Linux CRITICAL 9.8
CVE-2010-4344 KEVEPSS 72%

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SM…

Fix: 4.70+
Fix from $2,300 2010-12-14
Lintian CRITICAL 9.8
CVE-2009-4013EPSS 6%

Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers …

Fix: 2.3.2+
Fix from $2,300 2010-02-02
Debian Linux CRITICAL 9.8
CVE-2009-1151 KEVEPSS 95%

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitr…

Fix: 2.11.9.5 / 3.1.3.1+
Fix from $2,300 2009-03-26
Debian Linux CRITICAL 9.8
CVE-2008-0062EPSS 10%

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of servic…

Fix: after 1.6.3
Fix from $2,300 2008-03-19
Debian Linux CRITICAL 9.8
CVE-2005-3120EPSS 23%

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article…

Fix: after 2.8.6
Fix from $2,300 2005-10-17
Debian Linux CRITICAL 9.8
CVE-2005-1689EPSS 11%

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code …

Fix: 10.4.2+
Fix from $2,300 2005-07-18
Debian Linux CRITICAL 9.8
CVE-2005-0102

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code vi…

Fix: after 2.0.2
Fix from $2,300 2005-01-24
Debian Linux CRITICAL 9.8
CVE-2004-0772EPSS 7%

Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbit…

Fix: after 1.2.8
Fix from $2,300 2004-10-20
Debian Linux CRITICAL 9.8
CVE-2004-0434EPSS 7%

k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing …

Fix: 0.6.2+
Fix from $2,300 2004-07-07