Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.5
CVE-2016-5403

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QE…

Patch available
Fix from $1,600 2016-08-02
Ubuntu Linux CRITICAL 9.8
CVE-2016-3955EPSS 26%

The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attackers to cause a denial of servi…

Fix: 3.2.80 / 3.10.102+
Fix from $2,300 2016-07-03
Ubuntu Linux HIGH 7.5
CVE-2016-5360EPSS 43%

HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access …

Mitigation only
Fix from $1,950 2016-06-30
Ubuntu Linux HIGH 8.8
CVE-2016-4971EPSS 46%

GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

Fix: 1.18+
Fix from $1,950 2016-06-30
Ubuntu Linux HIGH 8.1
CVE-2016-4472EPSS 12%

The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of servi…

Fix: 2.7.15 / 3.3.7+
Fix from $1,950 2016-06-30
Ubuntu Linux HIGH 7.5
CVE-2015-8899

Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA re…

Fix: after 2.75
Fix from $1,950 2016-06-30
Ubuntu Linux HIGH 7.5
CVE-2016-5300EPSS 7%

The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of servic…

Fix: 2.2.0+
Fix from $1,950 2016-06-16
Ubuntu Linux MEDIUM 6.0
CVE-2016-2841

The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause …

Fix: after 2.5.0
Fix from $1,600 2016-06-16
Ubuntu Linux MEDIUM 6.5
CVE-2016-2392

The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descrip…

Mitigation only
Fix from $1,600 2016-06-16
Ubuntu Linux MEDIUM 5.0
CVE-2016-2391

The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of s…

Fix: after 2.5.1.1
Fix from $1,600 2016-06-16
Ubuntu Linux MEDIUM 5.9
CVE-2012-6702

Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat …

Fix: 2.2.0+
Fix from $1,600 2016-06-16
Ubuntu Linux HIGH 7.8
CVE-2016-5338

The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU …

Fix: after 2.6.2
Fix from $1,950 2016-06-14
Ubuntu Linux MEDIUM 5.5
CVE-2016-5337

The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via …

Fix: after 2.6.2
Fix from $1,600 2016-06-14
Ubuntu Linux HIGH 7.5
CVE-2016-4579

Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "ret…

Fix: after 1.3.3
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4574

Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of serv…

Fix: after 1.3.3
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4356

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds r…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4355

Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data,…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4354

ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via cra…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4353

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (a…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Ubuntu Linux MEDIUM 5.3
CVE-2016-5104

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and c…

Fix: after 1.2.0
Fix from $1,600 2016-06-13
Ubuntu Linux HIGH 8.8
CVE-2016-2834

Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (me…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 8.8
CVE-2016-2831

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allo…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Ubuntu Linux MEDIUM 6.5
CVE-2016-2829

Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission request…

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Ubuntu Linux HIGH 8.8
CVE-2016-2828

Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via We…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Ubuntu Linux MEDIUM 6.5
CVE-2016-2825

Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Ubuntu Linux MEDIUM 5.9
CVE-2016-4429

Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to caus…

Fix: 2.24+
Fix from $1,600 2016-06-10
Ubuntu Linux HIGH 7.5
CVE-2016-4447EPSS 14%

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buff…

Fix: after 10.11.5
Fix from $1,950 2016-06-09
Ubuntu Linux MEDIUM 5.5
CVE-2016-1582

LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access …

Mitigation only
Fix from $1,600 2016-06-09
Ubuntu Linux MEDIUM 5.5
CVE-2016-1581

LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and…

Fix: after 2.0.1
Fix from $1,600 2016-06-09
Ubuntu Linux HIGH 7.5
CVE-2016-4450EPSS 16%

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference an…

Fix: 1.10.1+
Fix from $1,950 2016-06-07