Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux CRITICAL 9.8
CVE-2016-0639EPSS 8%

Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and…

Fix: after 5.7.11
Fix from $2,300 2016-04-21
Enterprise Linux Desktop CRITICAL 9.8
CVE-2010-5325EPSS 5%

Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of se…

Fix: after 4.0.5
Fix from $2,300 2016-04-15
Openshift CRITICAL 9.8
CVE-2016-0791

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to…

Fix: after 1.649
Fix from $2,300 2016-04-07
Enterprise Linux Desktop CRITICAL 9.0
CVE-2015-7512EPSS 8%

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial…

Mitigation only
Fix from $2,300 2016-01-08
Openshift CRITICAL 9.8
CVE-2015-5254EPSS 35%

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2016-01-08
Openshift Container Platform CRITICAL 9.8
CVE-2015-8103EPSS 87%

The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…

Fix: 1.625.2 / 1.638+
Fix from $2,300 2015-11-25
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5123 KEVEPSS 18%

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wind…

Fix: after 18.0.0.203
Fix from $2,300 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5122 KEVEPSS 94%

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on W…

Fix: after 18.0.0.204
Fix from $2,300 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5119 KEVEPSS 99%

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x…

Fix: after 18.0.0.194
Fix from $2,300 2015-07-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-0192

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…

Fix: 5.0.16.10 / 6.1.8.4+
Fix from $2,300 2015-07-02
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3113 KEVEPSS 100%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46…

Fix: 11.2.202.468 / 13.0.0.296+
Fix from $2,300 2015-06-23
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3043 KEVEPSS 74%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: 11.2.202.457 / 13.0.0.281+
Fix from $2,300 2015-04-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2013-2729 KEVEPSS 67%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code…

Fix: 9.5.5 / 10.1.7+
Fix from $2,300 2013-05-16
Enterprise Virtualization CRITICAL 9.8
CVE-2013-1591

Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent …

Fix: 15.4+
Fix from $2,300 2013-01-31
Enterprise Linux Desktop CRITICAL 9.8
CVE-2012-4681 KEVEPSS 99%

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a…

Mitigation only
Fix from $2,300 2012-08-28
Enterprise Linux Server CRITICAL 9.8
CVE-2012-3503

The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default in…

Fix: after 1.0
Fix from $2,300 2012-08-25
Icedtea6 CRITICAL 9.8
CVE-2012-1723 KEVEPSS 94%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update…

Fix: 1.10.8 / 1.11.3+
Fix from $2,300 2012-06-16
Enterprise Linux Server CRITICAL 9.9
CVE-2009-3616

Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on…

Fix: after 0.10.6
Fix from $2,300 2009-10-23
Satellite CRITICAL 9.1
CVE-2008-2369

manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the ser…

Fix: 5.1.1+
Fix from $2,300 2008-08-14
Wu Ftpd CRITICAL 9.8
CVE-2003-0466EPSS 78%

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demon…

Fix: after 5.0
Fix from $2,300 2003-08-27
Linux CRITICAL 9.8
CVE-1999-0043EPSS 45%

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

Mitigation only
Fix from $2,300 1996-12-04