Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Image MEDIUM 5.9
CVE-2017-10600

ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files in the resulting image with the uid of the invoking user. When the result…

Mitigation only
Fix from $1,600 2017-07-11
Ubuntu Linux HIGH 7.8
CVE-2017-11111

In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash…

Mitigation only
Fix from $1,950 2017-07-08
Ubuntu Linux HIGH 7.8
CVE-2017-10686

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the to…

Patch available
Fix from $1,950 2017-06-29
Ubuntu Linux HIGH 7.5
CVE-2015-5180EPSS 6%

res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).

Fix: after 2.24
Fix from $1,950 2017-06-27
Ubuntu Linux HIGH 8.8
CVE-2017-9935

In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different…

Fix: after 4.0.8
Fix from $1,950 2017-06-26
Ubuntu Linux MEDIUM 6.5
CVE-2017-9815

In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a d…

Mitigation only
Fix from $1,600 2017-06-22
Ubuntu Linux MEDIUM 5.5
CVE-2017-9471

In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and applicatio…

No fix yet
Fix from $1,600 2017-06-07
Ubuntu Linux MEDIUM 5.5
CVE-2017-9473

In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.

No fix yet
Fix from $1,600 2017-06-07
Ubuntu Linux MEDIUM 5.9
CVE-2017-6512

Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary fil…

Fix: 2.13+
Fix from $1,600 2017-06-01
Juju CRITICAL 9.8
CVE-2017-9232EPSS 49%

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege…

Fix: after 1.25.12
Fix from $2,300 2017-05-28
Ubuntu Linux MEDIUM 6.5
CVE-2017-9239

An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value o…

No fix yet
Fix from $1,600 2017-05-26
Ubuntu Linux MEDIUM 5.5
CVE-2017-9208

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r…

Patch available
Fix from $1,600 2017-05-23
Ubuntu Linux MEDIUM 5.5
CVE-2017-9209

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r…

Patch available
Fix from $1,600 2017-05-23
Ubuntu Linux MEDIUM 5.5
CVE-2017-9210

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, r…

Mitigation only
Fix from $1,600 2017-05-23
Ubuntu Linux CRITICAL 9.8
CVE-2017-9058

In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

Fix: after 1.9.2
Fix from $2,300 2017-05-18
Ubuntu Linux CRITICAL 9.1
CVE-2017-6519

avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows …

Fix: after 0.6.32
Fix from $2,300 2017-05-01
Ubuntu Linux HIGH 7.7
CVE-2015-8567EPSS 6%

Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).

Fix: after 2.5.1.1
Fix from $1,950 2017-04-13
Ubuntu Linux HIGH 7.5
CVE-2017-5936

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote…

Fix: after 13.1.0
Fix from $1,950 2017-04-12
Ubuntu Linux HIGH 7.3
CVE-2017-7358

In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations an…

Fix: after 1.22.0
Fix from $1,950 2017-04-05
Ubuntu Core MEDIUM 5.9
CVE-2017-6507

An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or syste…

Fix: after 2.11
Fix from $1,600 2017-03-24
Ubuntu Linux MEDIUM 5.5
CVE-2016-9388

The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafte…

Fix: 1.900.14+
Fix from $1,600 2017-03-23
Ubuntu Linux CRITICAL 9.8
CVE-2014-9847

The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.

Patch available
Fix from $2,300 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9848

Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).

Patch available
Fix from $1,950 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9849

The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).

Patch available
Fix from $1,950 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9850

Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).

Patch available
Fix from $1,950 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9851

ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).

Patch available
Fix from $1,950 2017-03-20
Ubuntu Linux CRITICAL 9.8
CVE-2014-9841

The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to …

Patch available
Fix from $2,300 2017-03-20
Ubuntu Linux CRITICAL 9.8
CVE-2014-9843

The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.

Patch available
Fix from $2,300 2017-03-20
Ubuntu Linux CRITICAL 9.8
CVE-2014-9846

Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.

Patch available
Fix from $2,300 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9842

Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consump…

Patch available
Fix from $1,950 2017-03-20