Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2015-2301EPSS 15%

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers…

Fix: 5.4.40 / 5.5.22+
Fix from $1,950 2015-03-30
Ubuntu Linux MEDIUM 5.0
CVE-2014-8121EPSS 6%

DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if…

Fix: after 2.21
Fix from $1,600 2015-03-27
Ubuntu Linux HIGH 7.5
CVE-2015-2265

The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via cons…

Fix: after 1.0.65
Fix from $1,950 2015-03-24
Ubuntu Linux MEDIUM 6.4
CVE-2015-0250EPSS 17%

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers t…

Fix: after 6.1.2
Fix from $1,600 2015-03-24
Ubuntu Linux HIGH 8.5
CVE-2015-1803

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps i…

Fix: after 1.4.8
Fix from $1,950 2015-03-20
Ubuntu Linux MEDIUM 6.4
CVE-2015-2304

Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathn…

Fix: after 3.1.2
Fix from $1,600 2015-03-15
Ubuntu Linux HIGH 7.5
CVE-2015-2238

Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of…

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Ubuntu Linux MEDIUM 5.0
CVE-2015-1229

net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status c…

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Ubuntu Linux HIGH 7.5
CVE-2015-1228

The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force …

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Ubuntu Linux HIGH 7.5
CVE-2015-1215

The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly ha…

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Ubuntu Linux MEDIUM 5.0
CVE-2015-0832

Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows m…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Ubuntu Linux MEDIUM 6.8
CVE-2015-0829EPSS 6%

Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is im…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Ubuntu Linux MEDIUM 5.0
CVE-2015-0830

The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Ubuntu Linux MEDIUM 5.0
CVE-2015-0824

The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of ser…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Ubuntu Linux HIGH 7.5
CVE-2015-0823

Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger proble…

Fix: after 35.0.1
Fix from $1,950 2015-02-25
Ubuntu Linux HIGH 7.8
CVE-2014-9402EPSS 8%

The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is…

Fix: after 2.20
Fix from $1,950 2015-02-24
Ubuntu Linux HIGH 7.5
CVE-2015-1315

Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a craf…

Patch available
Fix from $1,950 2015-02-23
Ubuntu Linux MEDIUM 5.0
CVE-2014-9675

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers…

No fix yet
Fix from $1,600 2015-02-08
Ubuntu Linux HIGH 7.5
CVE-2014-9674EPSS 6%

The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original v…

Patch available
Fix from $1,950 2015-02-08
Ubuntu Linux MEDIUM 6.8
CVE-2014-9673

Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial o…

No fix yet
Fix from $1,600 2015-02-08
Ubuntu Linux MEDIUM 6.8
CVE-2014-9669

Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memor…

Patch available
Fix from $1,600 2015-02-08
Ubuntu Linux MEDIUM 6.8
CVE-2014-9666

The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count v…

Patch available
Fix from $1,600 2015-02-08
Ubuntu Linux HIGH 7.5
CVE-2014-9661

type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attacke…

No fix yet
Fix from $1,950 2015-02-08
Ubuntu Linux HIGH 7.5
CVE-2014-9660EPSS 5%

The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attack…

Patch available
Fix from $1,950 2015-02-08
Ubuntu Linux HIGH 7.5
CVE-2014-9658EPSS 5%

The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to…

Patch available
Fix from $1,950 2015-02-08
Ubuntu Linux MEDIUM 5.0
CVE-2014-9636EPSS 12%

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size s…

Patch available
Fix from $1,600 2015-02-06
Ubuntu Linux HIGH 7.5
CVE-2015-1205

Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 40.0.2214.94
Fix from $1,950 2015-01-22
Ubuntu Linux MEDIUM 5.0
CVE-2014-7943

Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Ubuntu Linux HIGH 7.2
CVE-2015-0412

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via v…

Patch available
Fix from $1,950 2015-01-21
Ubuntu Linux HIGH 7.5
CVE-2015-0411EPSS 10%

Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integ…

Fix: 5.5.41 / 10.0.16+
Fix from $1,950 2015-01-21