Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.2
CVE-2015-5199

Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable.

Fix: after 1.1.0
Fix from $1,950 2015-09-08
Ubuntu Linux HIGH 7.2
CVE-2015-5198

libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDP…

Fix: after 1.1.0
Fix from $1,950 2015-09-08
Ubuntu Linux HIGH 7.5
CVE-2015-6826

The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows …

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Ubuntu Linux HIGH 7.5
CVE-2015-6824

The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote at…

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Ubuntu Linux HIGH 7.5
CVE-2015-6820

The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with…

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Ubuntu Linux HIGH 7.5
CVE-2015-6818

The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PN…

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Ubuntu Linux HIGH 7.5
CVE-2015-3308

Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspec…

Fix: after 3.3.13
Fix from $1,950 2015-09-02
Ubuntu Linux MEDIUM 5.0
CVE-2015-6727

The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determin…

Fix: after 1.23.9
Fix from $1,600 2015-09-01
Ubuntu Linux MEDIUM 6.8
CVE-2015-4491EPSS 8%

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox…

Fix: after 2.31.4
Fix from $1,600 2015-08-16
Ubuntu Linux HIGH 7.5
CVE-2015-4488

Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Ubuntu Linux HIGH 10.0
CVE-2015-4486EPSS 7%

The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrar…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Ubuntu Linux MEDIUM 5.0
CVE-2015-4484

The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 …

Fix: after 39.0.3
Fix from $1,600 2015-08-16
Ubuntu Linux HIGH 9.3
CVE-2015-4480EPSS 6%

Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 …

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Ubuntu Linux MEDIUM 5.0
CVE-2015-4478

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which a…

Fix: after 39.0.3
Fix from $1,600 2015-08-16
Ubuntu Linux HIGH 10.0
CVE-2015-4477EPSS 6%

Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Ubuntu Linux HIGH 10.0
CVE-2015-4474EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Ubuntu Linux HIGH 10.0
CVE-2015-4473EPSS 7%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to …

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Ubuntu Linux MEDIUM 5.0
CVE-2013-7443

Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.

No fix yet
Fix from $1,600 2015-08-12
Ubuntu Linux MEDIUM 6.8
CVE-2015-5522

Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) v…

Fix: after 10.6.8
Fix from $1,600 2015-08-11
Ubuntu Linux MEDIUM 6.8
CVE-2015-1872

The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Fra…

Fix: after 2.5.3
Fix from $1,600 2015-07-26
Ubuntu Linux CRITICAL 9.8
CVE-2015-2590 KEVEPSS 25%

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentialit…

Patch available
Fix from $2,300 2015-07-16
Ubuntu Linux HIGH 7.5
CVE-2015-3279EPSS 7%

Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or pos…

Fix: after 1.0.70
Fix from $1,950 2015-07-14
Ubuntu Linux HIGH 7.5
CVE-2015-3258EPSS 8%

Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to ca…

Fix: after 1.0.70
Fix from $1,950 2015-07-14
Ubuntu Linux HIGH 10.0
CVE-2015-2738

The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Ubuntu Linux MEDIUM 6.8
CVE-2015-1330

unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in…

Fix: after 0.86
Fix from $1,600 2015-07-01
Ubuntu Linux MEDIUM 6.8
CVE-2015-1851

OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users t…

Fix: after 2014.1.4
Fix from $1,600 2015-06-25
Ubuntu Linux MEDIUM 6.8
CVE-2015-3395

The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4…

Fix: after 10.6
Fix from $1,600 2015-06-16
Ubuntu Linux HIGH 7.5
CVE-2015-3209EPSS 10%

Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTP…

Mitigation only
Fix from $1,950 2015-06-15
Ubuntu Linux HIGH 7.5
CVE-2015-3905EPSS 7%

Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and po…

Patch available
Fix from $1,950 2015-06-08
Ubuntu Linux HIGH 8.5
CVE-2015-4004EPSS 8%

The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtai…

Fix: 4.3+
Fix from $1,950 2015-06-07