Vulnerability index

Browse CVEs

248 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2017-13168 An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233. Ubuntu Linux No fix yet Fix from $1,9502017-12-06 HIGH 8.1 CVE-2017-13082 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during t… Ubuntu Linux No fix yet Fix from $1,9502017-10-17 MEDIUM 6.8 CVE-2017-13084 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, a… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 6.8 CVE-2017-13086 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowi… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 5.3 CVE-2017-13078 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker withi… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 5.3 CVE-2017-13079 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 5.3 CVE-2017-13080 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker with… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 5.3 CVE-2017-13081 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group ke… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 5.3 CVE-2017-13087 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network M… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 5.3 CVE-2017-13088 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireles… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 MEDIUM 6.8 CVE-2017-13077 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allo… Ubuntu Linux Mitigation only Fix from $1,6002017-10-17 HIGH 8.8 CVE-2017-2888 An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer over… Ubuntu Linux No fix yet Fix from $1,9502017-10-11 MEDIUM 5.5 CVE-2017-14859 An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentat… Ubuntu Linux No fix yet Fix from $1,6002017-09-29 MEDIUM 5.5 CVE-2017-14862 An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fa… Ubuntu Linux No fix yet Fix from $1,6002017-09-29 MEDIUM 5.5 CVE-2017-14864 An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and… Ubuntu Linux No fix yet Fix from $1,6002017-09-29 MEDIUM 6.5 CVE-2017-14342 ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file. Ubuntu Linux No fix yet Fix from $1,6002017-09-12 MEDIUM 5.5 CVE-2017-14228 In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. … Ubuntu Linux No fix yet Fix from $1,6002017-09-09 MEDIUM 6.5 CVE-2017-11683 There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denia… Ubuntu Linux Mitigation only Fix from $1,6002017-07-27 HIGH 7.5 CVE-2017-11591 There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted in… Ubuntu Linux No fix yet Fix from $1,9502017-07-24 MEDIUM 5.9 CVE-2017-10600 ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files in the resulting image with the uid of the invoking user. When the result… Ubuntu Image Mitigation only Fix from $1,6002017-07-11 HIGH 7.8 CVE-2017-11111 In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash… Ubuntu Linux Mitigation only Fix from $1,9502017-07-08 MEDIUM 6.5 CVE-2017-9815 In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a d… Ubuntu Linux Mitigation only Fix from $1,6002017-06-22 MEDIUM 5.5 CVE-2017-9471 In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and applicatio… Ubuntu Linux No fix yet Fix from $1,6002017-06-07 MEDIUM 5.5 CVE-2017-9473 In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file. Ubuntu Linux No fix yet Fix from $1,6002017-06-07 MEDIUM 6.5 CVE-2017-9239 An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value o… Ubuntu Linux No fix yet Fix from $1,6002017-05-26 MEDIUM 5.5 CVE-2017-9210 libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r… Ubuntu Linux Mitigation only Fix from $1,6002017-05-23 HIGH 7.5 CVE-2016-5360EPSS 43% HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access … Ubuntu Linux Mitigation only Fix from $1,9502016-06-30 MEDIUM 6.5 CVE-2016-2392 The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descrip… Ubuntu Linux Mitigation only Fix from $1,6002016-06-16 MEDIUM 5.5 CVE-2016-1582 LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access … Ubuntu Linux Mitigation only Fix from $1,6002016-06-09 HIGH 7.1 CVE-2015-5261 Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL com… Ubuntu Linux Mitigation only Fix from $1,9502016-06-07