Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.5
CVE-2016-7795

The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 ha…

Fix: after 231
Fix from $1,600 2016-10-13
Ubuntu Linux HIGH 7.5
CVE-2016-7401EPSS 6%

The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass…

Fix: after 1.8.14
Fix from $1,950 2016-10-03
Ubuntu Linux HIGH 7.5
CVE-2016-6352

The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) v…

Fix: after 2.35.2
Fix from $1,950 2016-10-03
Ubuntu Linux MEDIUM 5.5
CVE-2016-1372

ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.

Fix: after 0.99.1
Fix from $1,600 2016-10-03
Ubuntu Linux MEDIUM 5.5
CVE-2016-1371

ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executabl…

Fix: after 0.99.1
Fix from $1,600 2016-10-03
Ubuntu Linux HIGH 7.5
CVE-2016-7162

The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a sym…

Patch available
Fix from $1,950 2016-09-26
Ubuntu Linux MEDIUM 5.5
CVE-2015-8934

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of …

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8933

Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.8
CVE-2015-8931

Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2…

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8932

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of s…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.5
CVE-2015-8930

bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member o…

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8928

The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8926

The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a den…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8925

The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8924EPSS 5%

The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a d…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 6.5
CVE-2015-8923

The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a …

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8922

The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (N…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.5
CVE-2015-8921EPSS 12%

The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) v…

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8920

The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.5
CVE-2015-8919

The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial …

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Ubuntu Linux MEDIUM 6.5
CVE-2015-8916

bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.5
CVE-2016-6262EPSS 7%

idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-…

Fix: after 1.32
Fix from $1,950 2016-09-07
Ubuntu Linux HIGH 7.5
CVE-2016-6261

The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read…

Fix: after 1.32
Fix from $1,950 2016-09-07
Ubuntu Linux HIGH 7.5
CVE-2015-8948EPSS 7%

idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an …

Fix: after 1.32
Fix from $1,950 2016-09-07
Ubuntu Linux MEDIUM 6.7
CVE-2016-6351

The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest …

Fix: after 2.6.2
Fix from $1,600 2016-09-07
Ubuntu Linux MEDIUM 6.0
CVE-2016-5107

The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrat…

Fix: after 2.6.2
Fix from $1,600 2016-09-02
Ubuntu Linux MEDIUM 6.0
CVE-2016-5106

The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allow…

Fix: after 2.6.2
Fix from $1,600 2016-09-02
Ubuntu Linux MEDIUM 6.0
CVE-2016-4952

QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a deni…

Fix: after 2.6.2
Fix from $1,600 2016-09-02
Ubuntu Linux HIGH 8.1
CVE-2016-5421EPSS 8%

Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact …

Fix: after 7.50.0
Fix from $1,950 2016-08-10
Ubuntu Linux HIGH 7.5
CVE-2016-6232

Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (…

Fix: after 5.24
Fix from $1,950 2016-08-02