Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.5
CVE-2016-3712

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by ed…

Patch available
Fix from $1,600 2016-05-11
Ubuntu Linux HIGH 7.5
CVE-2016-4555EPSS 54%

client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge S…

Patch available
Fix from $1,950 2016-05-10
Ubuntu Linux HIGH 8.6
CVE-2016-4553EPSS 80%

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remo…

Fix: after 3.5.17
Fix from $1,950 2016-05-10
Ubuntu Linux HIGH 7.5
CVE-2016-4476

hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attac…

Fix: after 2.5
Fix from $1,950 2016-05-09
Ubuntu Linux MEDIUM 5.9
CVE-2016-4008EPSS 26%

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows rem…

Fix: after 4.7
Fix from $1,600 2016-05-05
Ubuntu Linux MEDIUM 5.5
CVE-2016-3717EPSS 20%

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

Patch available
Fix from $1,600 2016-05-05
Ubuntu Linux HIGH 8.4
CVE-2016-3714 KEVEPSS 97%

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1…

Fix: after 6.9.3-9
Fix from $1,950 2016-05-05
Ubuntu Linux HIGH 7.5
CVE-2016-2117EPSS 6%

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which a…

Fix: after 4.5.2
Fix from $1,950 2016-05-02
Ubuntu Core HIGH 7.8
CVE-2016-1576

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privi…

Fix: after 4.5.2
Fix from $1,950 2016-05-02
Ubuntu Linux HIGH 7.8
CVE-2016-3672

The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which…

Fix: after 4.5.2
Fix from $1,950 2016-04-27
Ubuntu Linux MEDIUM 5.5
CVE-2016-3156

The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of s…

Fix: after 4.5.1
Fix from $1,600 2016-04-27
Ubuntu Linux HIGH 7.4
CVE-2016-2069

Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure…

Fix: after 4.4
Fix from $1,950 2016-04-27
Ubuntu Linux HIGH 8.1
CVE-2016-4054EPSS 78%

Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI…

Mitigation only
Fix from $1,950 2016-04-25
Ubuntu Linux HIGH 8.1
CVE-2016-4052EPSS 13%

Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execu…

Patch available
Fix from $1,950 2016-04-25
Ubuntu Linux HIGH 8.8
CVE-2016-4051EPSS 18%

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or ex…

Patch available
Fix from $1,950 2016-04-25
Ubuntu Linux MEDIUM 5.9
CVE-2016-2115EPSS 10%

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which…

Patch available
Fix from $1,600 2016-04-25
Ubuntu Linux MEDIUM 5.9
CVE-2016-2114

The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mand…

Patch available
Fix from $1,600 2016-04-25
Ubuntu Linux HIGH 7.4
CVE-2016-2113

Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-midd…

Patch available
Fix from $1,950 2016-04-25
Ubuntu Linux MEDIUM 5.9
CVE-2016-2112EPSS 9%

The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sa…

Patch available
Fix from $1,600 2016-04-25
Ubuntu Linux MEDIUM 6.3
CVE-2016-2111

The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows r…

Patch available
Fix from $1,600 2016-04-25
Ubuntu Linux MEDIUM 5.9
CVE-2016-2110EPSS 8%

The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle att…

Patch available
Fix from $1,600 2016-04-25
Ubuntu Linux MEDIUM 5.9
CVE-2015-5370EPSS 19%

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attack…

Patch available
Fix from $1,600 2016-04-25
Ubuntu Linux MEDIUM 6.5
CVE-2013-7449

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a do…

Fix: after 2.10.1
Fix from $1,600 2016-04-21
Ubuntu Linux MEDIUM 5.5
CVE-2015-7802

gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted…

Mitigation only
Fix from $1,600 2016-04-20
Ubuntu Linux HIGH 8.8
CVE-2015-7801EPSS 5%

Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.

Fix: after 0.6.4
Fix from $1,950 2016-04-20
Ubuntu Linux CRITICAL 9.8
CVE-2015-8779EPSS 6%

Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause…

No fix yet
Fix from $2,300 2016-04-19
Ubuntu Linux CRITICAL 9.1
CVE-2015-8776

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (applicat…

Mitigation only
Fix from $2,300 2016-04-19
Ubuntu Linux HIGH 8.8
CVE-2014-9765

Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a …

Fix: after 3.0.8
Fix from $1,950 2016-04-19
Ubuntu Linux MEDIUM 5.5
CVE-2016-3941

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a deni…

Fix: after 2.1.6
Fix from $1,600 2016-04-18
Ubuntu Linux MEDIUM 5.5
CVE-2016-3961

Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a d…

Fix: after 4.5.3
Fix from $1,600 2016-04-15