Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.8
CVE-2015-4047EPSS 10%

racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a serie…

Fix: after 12.1.4
Fix from $1,950 2015-05-29
Ubuntu Linux HIGH 7.8
CVE-2015-0847

nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of se…

Fix: after 3.10
Fix from $1,950 2015-05-29
Ubuntu Linux HIGH 7.2
CVE-2015-3409

Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the curren…

Fix: after 0.74
Fix from $1,950 2015-05-19
Ubuntu Linux HIGH 10.0
CVE-2015-3408EPSS 6%

Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled …

Fix: after 0.73
Fix from $1,950 2015-05-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-3407

Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.

Fix: after 0.73
Fix from $1,600 2015-05-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-2668

ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.

Fix: after 0.98.6
Fix from $1,600 2015-05-12
Ubuntu Linux MEDIUM 5.0
CVE-2015-2222

ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.

Fix: after 0.98.6
Fix from $1,600 2015-05-12
Ubuntu Linux MEDIUM 5.0
CVE-2015-2221

ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.

Fix: after 0.98.6
Fix from $1,600 2015-05-12
Ubuntu Linux MEDIUM 5.0
CVE-2015-2170

The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

Fix: after 0.98.6
Fix from $1,600 2015-05-12
Ubuntu Linux HIGH 7.5
CVE-2015-1250

Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact…

Fix: after 42.0.2311.87
Fix from $1,950 2015-05-01
Ubuntu Linux MEDIUM 6.8
CVE-2015-1321

Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or …

Fix: after 1.6.4
Fix from $1,600 2015-04-29
Ubuntu Linux MEDIUM 5.8
CVE-2015-1863EPSS 5%

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly e…

No fix yet
Fix from $1,600 2015-04-28
Ubuntu Linux MEDIUM 6.8
CVE-2015-1774EPSS 8%

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of ser…

Fix: after 4.3.6
Fix from $1,600 2015-04-28
Ubuntu Linux HIGH 7.5
CVE-2015-3416EPSS 6%

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions…

Fix: 5.4.42 / 5.5.26+
Fix from $1,950 2015-04-24
Ubuntu Linux MEDIUM 5.0
CVE-2015-1244

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the w…

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Ubuntu Linux HIGH 7.5
CVE-2015-1242

The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90…

Fix: after 42.0.2311.60
Fix from $1,950 2015-04-19
Ubuntu Linux HIGH 7.5
CVE-2015-1237

Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0…

Fix: after 42.0.2311.60
Fix from $1,950 2015-04-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-1235

The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90…

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Ubuntu Linux MEDIUM 5.5
CVE-2015-1856

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an…

Fix: after 2.2.2
Fix from $1,600 2015-04-17
Ubuntu Linux HIGH 7.5
CVE-2013-7439

Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote at…

Patch available
Fix from $1,950 2015-04-16
Ubuntu Linux HIGH 7.6
CVE-2015-2775EPSS 8%

Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via…

Fix: after 2.1.19
Fix from $1,950 2015-04-13
Ubuntu Linux HIGH 10.0
CVE-2015-2806EPSS 8%

Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.

Fix: after 4.3
Fix from $1,950 2015-04-10
Ubuntu Linux HIGH 7.5
CVE-2015-1317

Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly ex…

Fix: after 1.5.5
Fix from $1,950 2015-04-08
Ubuntu Linux MEDIUM 6.4
CVE-2015-1473

The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a ris…

Fix: after 2.20
Fix from $1,600 2015-04-08
Ubuntu Linux HIGH 7.5
CVE-2015-1472

The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memor…

Fix: after 2.20
Fix from $1,950 2015-04-08
Ubuntu Linux MEDIUM 5.0
CVE-2015-0808

The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deal…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Ubuntu Linux HIGH 7.5
CVE-2015-0806

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length du…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Ubuntu Linux HIGH 7.5
CVE-2015-0803

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value duri…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Ubuntu Linux MEDIUM 5.0
CVE-2015-0802EPSS 67%

Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might a…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Ubuntu Linux MEDIUM 6.8
CVE-2015-2305EPSS 8%

Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in Net…

Fix: 5.4.39 / 5.5.23+
Fix from $1,600 2015-03-30