Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.5
CVE-2016-1897EPSS 15%

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (H…

No fix yet
Fix from $1,600 2016-01-15
Ubuntu Linux MEDIUM 5.5
CVE-2016-1898EPSS 13%

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (…

No fix yet
Fix from $1,600 2016-01-15
Ubuntu Linux HIGH 7.3
CVE-2015-8607

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, wh…

Fix: after 3.61
Fix from $1,950 2016-01-13
Ubuntu Linux HIGH 8.6
CVE-2015-1779EPSS 7%

The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket p…

Patch available
Fix from $1,950 2016-01-12
Ubuntu Linux CRITICAL 9.0
CVE-2015-8557EPSS 7%

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary command…

No fix yet
Fix from $2,300 2016-01-08
Ubuntu Linux HIGH 7.5
CVE-2015-7540EPSS 7%

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, whi…

Fix: 4.1.22+
Fix from $1,950 2015-12-29
Ubuntu Linux HIGH 7.2
CVE-2015-5252EPSS 13%

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships e…

Fix: 4.1.22 / 4.2.7+
Fix from $1,950 2015-12-29
Ubuntu Linux MEDIUM 5.8
CVE-2015-8242

The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a…

Fix: after 2.9.2
Fix from $1,600 2015-12-15
Ubuntu Linux MEDIUM 5.0
CVE-2015-7499EPSS 6%

Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process…

Fix: after 10.11.3
Fix from $1,600 2015-12-15
Ubuntu Linux MEDIUM 5.0
CVE-2015-7498EPSS 7%

Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial o…

Mitigation only
Fix from $1,600 2015-12-15
Ubuntu Linux HIGH 7.1
CVE-2015-5312

The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependen…

Fix: after 10.11.3
Fix from $1,950 2015-12-15
Ubuntu Linux HIGH 7.2
CVE-2015-1344

The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writin…

Fix: after 0.11
Fix from $1,950 2015-12-07
Ubuntu Linux HIGH 7.5
CVE-2015-0860EPSS 5%

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1…

Mitigation only
Fix from $1,950 2015-12-03
Ubuntu Linux MEDIUM 6.8
CVE-2015-8365

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the d…

Mitigation only
Fix from $1,600 2015-11-26
Ubuntu Linux MEDIUM 6.8
CVE-2015-8364

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows re…

Mitigation only
Fix from $1,600 2015-11-26
Ubuntu Linux MEDIUM 5.0
CVE-2015-7981EPSS 6%

The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to o…

Patch available
Fix from $1,600 2015-11-24
Ubuntu Linux MEDIUM 6.6
CVE-2015-7869

Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.8…

Fix: 304.131 / 340.96+
Fix from $1,600 2015-11-24
Ubuntu Linux MEDIUM 5.0
CVE-2014-9756

The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via uns…

Fix: 1.0.26+
Fix from $1,600 2015-11-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-8023

The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly val…

Mitigation only
Fix from $1,600 2015-11-18
Ubuntu Linux MEDIUM 5.0
CVE-2015-0272EPSS 5%

GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Adverti…

Fix: 1.2.0+
Fix from $1,600 2015-11-17
Ubuntu Linux MEDIUM 6.8
CVE-2015-5214EPSS 10%

LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corrupt…

Fix: after 4.4.5
Fix from $1,600 2015-11-10
Ubuntu Linux MEDIUM 6.8
CVE-2015-5213EPSS 13%

Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corrupti…

Fix: after 4.4.4
Fix from $1,600 2015-11-10
Ubuntu Linux MEDIUM 5.0
CVE-2015-2695EPSS 6%

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to …

Fix: 1.14+
Fix from $1,600 2015-11-09
Ubuntu Linux MEDIUM 6.8
CVE-2015-7696EPSS 7%

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbit…

Mitigation only
Fix from $1,600 2015-11-06
Ubuntu Linux MEDIUM 6.8
CVE-2015-7674EPSS 6%

Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of ser…

Fix: after 2.32.0
Fix from $1,600 2015-10-26
Ubuntu Linux MEDIUM 6.8
CVE-2015-1337

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk imag…

No fix yet
Fix from $1,600 2015-10-09
Ubuntu Linux HIGH 7.5
CVE-2015-7236EPSS 6%

Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (…

Fix: after 0.2.1
Fix from $1,950 2015-10-01
Ubuntu Linux HIGH 7.2
CVE-2015-1338

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symli…

Fix: after 2.18.1
Fix from $1,950 2015-10-01
Ubuntu Linux HIGH 7.2
CVE-2015-1335

lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (…

Fix: after 1.0.7
Fix from $1,950 2015-10-01
Ubuntu Linux MEDIUM 6.3
CVE-2015-5200

The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via uns…

Fix: after 1.1.0
Fix from $1,600 2015-09-08