Vulnerability index

Browse CVEs

248 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.8
CVE-2017-13168

An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.

No fix yet
Fix from $1,950 2017-12-06
Ubuntu Linux HIGH 8.1
CVE-2017-13082

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during t…

No fix yet
Fix from $1,950 2017-10-17
Ubuntu Linux MEDIUM 6.8
CVE-2017-13084

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, a…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 6.8
CVE-2017-13086

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowi…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13078

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker withi…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13079

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13080

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker with…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13081

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group ke…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13087

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network M…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13088

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireles…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 6.8
CVE-2017-13077

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allo…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux HIGH 8.8
CVE-2017-2888

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer over…

No fix yet
Fix from $1,950 2017-10-11
Ubuntu Linux MEDIUM 5.5
CVE-2017-14859

An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentat…

No fix yet
Fix from $1,600 2017-09-29
Ubuntu Linux MEDIUM 5.5
CVE-2017-14862

An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fa…

No fix yet
Fix from $1,600 2017-09-29
Ubuntu Linux MEDIUM 5.5
CVE-2017-14864

An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and…

No fix yet
Fix from $1,600 2017-09-29
Ubuntu Linux MEDIUM 6.5
CVE-2017-14342

ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.

No fix yet
Fix from $1,600 2017-09-12
Ubuntu Linux MEDIUM 5.5
CVE-2017-14228

In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. …

No fix yet
Fix from $1,600 2017-09-09
Ubuntu Linux MEDIUM 6.5
CVE-2017-11683

There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denia…

Mitigation only
Fix from $1,600 2017-07-27
Ubuntu Linux HIGH 7.5
CVE-2017-11591

There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted in…

No fix yet
Fix from $1,950 2017-07-24
Ubuntu Image MEDIUM 5.9
CVE-2017-10600

ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files in the resulting image with the uid of the invoking user. When the result…

Mitigation only
Fix from $1,600 2017-07-11
Ubuntu Linux HIGH 7.8
CVE-2017-11111

In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash…

Mitigation only
Fix from $1,950 2017-07-08
Ubuntu Linux MEDIUM 6.5
CVE-2017-9815

In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a d…

Mitigation only
Fix from $1,600 2017-06-22
Ubuntu Linux MEDIUM 5.5
CVE-2017-9471

In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and applicatio…

No fix yet
Fix from $1,600 2017-06-07
Ubuntu Linux MEDIUM 5.5
CVE-2017-9473

In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.

No fix yet
Fix from $1,600 2017-06-07
Ubuntu Linux MEDIUM 6.5
CVE-2017-9239

An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value o…

No fix yet
Fix from $1,600 2017-05-26
Ubuntu Linux MEDIUM 5.5
CVE-2017-9210

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r…

Mitigation only
Fix from $1,600 2017-05-23
Ubuntu Linux HIGH 7.5
CVE-2016-5360EPSS 43%

HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access …

Mitigation only
Fix from $1,950 2016-06-30
Ubuntu Linux MEDIUM 6.5
CVE-2016-2392

The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descrip…

Mitigation only
Fix from $1,600 2016-06-16
Ubuntu Linux MEDIUM 5.5
CVE-2016-1582

LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access …

Mitigation only
Fix from $1,600 2016-06-09
Ubuntu Linux HIGH 7.1
CVE-2015-5261

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL com…

Mitigation only
Fix from $1,950 2016-06-07