Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.5
CVE-2014-9844

The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a craf…

Patch available
Fix from $1,600 2017-03-20
Ubuntu Linux MEDIUM 5.5
CVE-2014-9845

The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.

Patch available
Fix from $1,600 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9854

coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of i…

Fix: 6.9.4-0+
Fix from $1,950 2017-03-17
Ubuntu Linux MEDIUM 5.5
CVE-2014-9853

Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-17
Ubuntu Linux HIGH 7.5
CVE-2016-10109

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsLi…

Fix: after 1.8.19
Fix from $1,950 2017-02-23
Ubuntu Linux CRITICAL 9.8
CVE-2015-8768

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to instal…

Patch available
Fix from $2,300 2017-02-13
Ubuntu Linux HIGH 7.1
CVE-2016-10165

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of servi…

Patch available
Fix from $1,950 2017-02-03
Ubuntu Linux MEDIUM 5.9
CVE-2016-9963

Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.

Fix: after 4.87
Fix from $1,600 2017-02-01
Ubuntu Linux MEDIUM 6.1
CVE-2016-9119

Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web …

Fix: after 1.9.7
Fix from $1,600 2017-01-30
Ubuntu Linux MEDIUM 5.5
CVE-2016-5824

libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.

Patch available
Fix from $1,600 2017-01-27
Ubuntu Linux HIGH 7.5
CVE-2016-7426EPSS 12%

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote…

Fix: 4.2.8 / 4.3.94+
Fix from $1,950 2017-01-13
Ubuntu Linux HIGH 8.1
CVE-2016-2377

A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potential…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Ubuntu Linux HIGH 8.1
CVE-2016-2378

A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially resu…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Ubuntu Linux HIGH 8.1
CVE-2016-2368

Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server coul…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Ubuntu Linux HIGH 8.1
CVE-2016-2371

An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cau…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Ubuntu Linux HIGH 8.1
CVE-2016-2374

An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Ubuntu Linux HIGH 8.1
CVE-2016-2376

A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potenti…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2365

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potent…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2366

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potent…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2367

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result i…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2369

A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2370

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could poten…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2372

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result i…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2373

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potent…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.3
CVE-2016-2375

An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the ser…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux HIGH 7.8
CVE-2016-9949EPSS 18%

An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it…

Fix: after 12.10
Fix from $1,950 2016-12-17
Ubuntu Linux HIGH 7.8
CVE-2016-9950EPSS 7%

An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These…

Fix: after 12.10
Fix from $1,950 2016-12-17
Ubuntu Linux HIGH 7.8
CVE-2015-1328EPSS 38%

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions …

Fix: after 15.04
Fix from $1,950 2016-11-28
Ubuntu Linux MEDIUM 5.5
CVE-2016-9318

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current docume…

Fix: after 2.9.4
Fix from $1,600 2016-11-16
Ubuntu Linux HIGH 7.0
CVE-2016-5195 KEVEPSS 84%

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of…

Fix: 3.2.83 / 3.4.113+
Fix from $1,950 2016-11-10