Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.9
CVE-2011-4600

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks…

Mitigation only
Fix from $1,600 2016-04-14
Ubuntu Linux HIGH 7.3
CVE-2015-8560EPSS 5%

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows rem…

Mitigation only
Fix from $1,950 2016-04-14
Ubuntu Linux HIGH 7.5
CVE-2015-8806

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected characte…

Fix: 2.9.4+
Fix from $1,950 2016-04-13
Ubuntu Linux HIGH 7.5
CVE-2015-3146

The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allo…

Fix: after 0.6.4
Fix from $1,950 2016-04-13
Ubuntu Linux HIGH 7.8
CVE-2016-3981

Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (…

Fix: after 0.7.5
Fix from $1,950 2016-04-13
Ubuntu Linux MEDIUM 6.5
CVE-2016-2191

The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write …

Patch available
Fix from $1,600 2016-04-13
Ubuntu Linux MEDIUM 5.7
CVE-2016-2116

Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory cons…

Fix: after 1.900.1
Fix from $1,600 2016-04-13
Ubuntu Linux HIGH 7.6
CVE-2016-1577

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (…

Fix: after 1.900.1
Fix from $1,950 2016-04-13
Ubuntu Linux CRITICAL 9.8
CVE-2014-9766EPSS 6%

Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (app…

Fix: after 0.32.5
Fix from $2,300 2016-04-13
Ubuntu Linux HIGH 7.5
CVE-2016-2118EPSS 37%

The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC conn…

Fix: 4.2.10 / 4.3.7+
Fix from $1,950 2016-04-12
Ubuntu Linux HIGH 7.8
CVE-2016-3157

The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which all…

Patch available
Fix from $1,950 2016-04-12
Ubuntu Linux HIGH 8.4
CVE-2016-2857

The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and c…

Mitigation only
Fix from $1,950 2016-04-12
Ubuntu Linux MEDIUM 6.5
CVE-2016-2858

QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process c…

Fix: after 2.5.1.1
Fix from $1,600 2016-04-07
Ubuntu Linux HIGH 8.2
CVE-2016-3947EPSS 15%

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remo…

Fix: after 3.5.15
Fix from $1,950 2016-04-07
Ubuntu Linux HIGH 8.8
CVE-2016-3679

Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial…

Fix: after 49.0.2623.95
Fix from $1,950 2016-03-29
Ubuntu Linux MEDIUM 6.5
CVE-2015-7560EPSS 13%

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote a…

Fix: 4.1.23 / 4.2.9+
Fix from $1,600 2016-03-13
Ubuntu Linux CRITICAL 9.8
CVE-2015-8805

The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…

Fix: after 3.1.1
Fix from $2,300 2016-02-23
Ubuntu Linux CRITICAL 9.8
CVE-2015-8804

x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-…

Fix: after 3.1.1
Fix from $2,300 2016-02-23
Ubuntu Linux CRITICAL 9.8
CVE-2015-8803

The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…

Fix: after 3.1.1
Fix from $2,300 2016-02-23
Ubuntu Linux HIGH 7.8
CVE-2016-0795

LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a cra…

Fix: after 5.0.4
Fix from $1,950 2016-02-18
Ubuntu Linux HIGH 7.8
CVE-2016-0794

The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified othe…

Fix: after 5.0.3
Fix from $1,950 2016-02-18
Ubuntu Linux MEDIUM 6.5
CVE-2013-7447

Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thun…

Patch available
Fix from $1,600 2016-02-17
Ubuntu Linux HIGH 8.8
CVE-2016-2330

libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of…

Fix: after 2.8.5
Fix from $1,950 2016-02-12
Ubuntu Linux HIGH 7.8
CVE-2015-8539

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl command…

Fix: 4.4+
Fix from $1,950 2016-02-08
Ubuntu Linux HIGH 8.4
CVE-2016-1572

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mount…

Fix: 109+
Fix from $1,950 2016-01-22
Ubuntu Linux HIGH 7.2
CVE-2016-0546

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.…

Fix: 5.5.47 / 10.0.23+
Fix from $1,950 2016-01-21
Ubuntu Linux HIGH 10.0
CVE-2016-0494EPSS 7%

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows rem…

Mitigation only
Fix from $1,950 2016-01-21
Ubuntu Linux HIGH 10.0
CVE-2016-0483EPSS 15%

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confi…

Patch available
Fix from $1,950 2016-01-21
Ubuntu Linux MEDIUM 5.0
CVE-2016-0466EPSS 5%

Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; an…

Mitigation only
Fix from $1,600 2016-01-21
Ubuntu Linux MEDIUM 5.0
CVE-2016-0402

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows rem…

Patch available
Fix from $1,600 2016-01-21