Vulnerability index

Browse CVEs

248 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2016-3705EPSS 5%

The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth…

Mitigation only
Fix from $1,950 2016-05-17
Ubuntu Core Launcher CRITICAL 9.8
CVE-2016-1580

The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when usi…

Mitigation only
Fix from $2,300 2016-05-13
Ubuntu Linux CRITICAL 9.8
CVE-2016-1578

Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecif…

Mitigation only
Fix from $2,300 2016-05-13
Ubuntu Linux HIGH 8.1
CVE-2016-4054EPSS 78%

Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI…

Mitigation only
Fix from $1,950 2016-04-25
Ubuntu Linux MEDIUM 5.5
CVE-2015-7802

gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted…

Mitigation only
Fix from $1,600 2016-04-20
Ubuntu Linux CRITICAL 9.8
CVE-2015-8779EPSS 6%

Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause…

No fix yet
Fix from $2,300 2016-04-19
Ubuntu Linux CRITICAL 9.1
CVE-2015-8776

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (applicat…

Mitigation only
Fix from $2,300 2016-04-19
Ubuntu Linux MEDIUM 5.9
CVE-2011-4600

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks…

Mitigation only
Fix from $1,600 2016-04-14
Ubuntu Linux HIGH 7.3
CVE-2015-8560EPSS 5%

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows rem…

Mitigation only
Fix from $1,950 2016-04-14
Ubuntu Linux HIGH 8.4
CVE-2016-2857

The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and c…

Mitigation only
Fix from $1,950 2016-04-12
Ubuntu Linux HIGH 10.0
CVE-2016-0494EPSS 7%

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows rem…

Mitigation only
Fix from $1,950 2016-01-21
Ubuntu Linux MEDIUM 5.0
CVE-2016-0466EPSS 5%

Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; an…

Mitigation only
Fix from $1,600 2016-01-21
Ubuntu Linux MEDIUM 5.5
CVE-2016-1897EPSS 15%

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (H…

No fix yet
Fix from $1,600 2016-01-15
Ubuntu Linux MEDIUM 5.5
CVE-2016-1898EPSS 13%

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (…

No fix yet
Fix from $1,600 2016-01-15
Ubuntu Linux CRITICAL 9.0
CVE-2015-8557EPSS 7%

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary command…

No fix yet
Fix from $2,300 2016-01-08
Ubuntu Linux MEDIUM 5.0
CVE-2015-7498EPSS 7%

Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial o…

Mitigation only
Fix from $1,600 2015-12-15
Ubuntu Linux HIGH 7.5
CVE-2015-0860EPSS 5%

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1…

Mitigation only
Fix from $1,950 2015-12-03
Ubuntu Linux MEDIUM 6.8
CVE-2015-8365

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the d…

Mitigation only
Fix from $1,600 2015-11-26
Ubuntu Linux MEDIUM 6.8
CVE-2015-8364

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows re…

Mitigation only
Fix from $1,600 2015-11-26
Ubuntu Linux MEDIUM 5.0
CVE-2015-8023

The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly val…

Mitigation only
Fix from $1,600 2015-11-18
Ubuntu Linux MEDIUM 6.8
CVE-2015-7696EPSS 7%

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbit…

Mitigation only
Fix from $1,600 2015-11-06
Ubuntu Linux MEDIUM 6.8
CVE-2015-1337

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk imag…

No fix yet
Fix from $1,600 2015-10-09
Ubuntu Linux MEDIUM 5.0
CVE-2013-7443

Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.

No fix yet
Fix from $1,600 2015-08-12
Ubuntu Linux HIGH 7.5
CVE-2015-3209EPSS 10%

Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTP…

Mitigation only
Fix from $1,950 2015-06-15
Ubuntu Linux MEDIUM 5.8
CVE-2015-1863EPSS 5%

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly e…

No fix yet
Fix from $1,600 2015-04-28
Ubuntu Linux MEDIUM 5.0
CVE-2014-9675

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers…

No fix yet
Fix from $1,600 2015-02-08
Ubuntu Linux MEDIUM 6.8
CVE-2014-9673

Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial o…

No fix yet
Fix from $1,600 2015-02-08
Ubuntu Linux HIGH 7.5
CVE-2014-9661

type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attacke…

No fix yet
Fix from $1,950 2015-02-08
Ubuntu Linux HIGH 10.0
CVE-2015-0408EPSS 7%

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availabili…

Mitigation only
Fix from $1,950 2015-01-21
Ubuntu Linux MEDIUM 5.0
CVE-2014-9221

strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Ke…

Mitigation only
Fix from $1,600 2015-01-07