Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.0
CVE-2015-0410EPSS 5%

Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 a…

Patch available
Fix from $1,600 2015-01-21
Ubuntu Linux HIGH 10.0
CVE-2015-0408EPSS 7%

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availabili…

Mitigation only
Fix from $1,950 2015-01-21
Ubuntu Linux MEDIUM 5.0
CVE-2015-0407

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors relate…

Patch available
Fix from $1,600 2015-01-21
Ubuntu Linux MEDIUM 5.0
CVE-2015-0400

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Lib…

Patch available
Fix from $1,600 2015-01-21
Ubuntu Linux HIGH 9.3
CVE-2015-0395EPSS 6%

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availabili…

Patch available
Fix from $1,950 2015-01-21
Ubuntu Linux MEDIUM 5.4
CVE-2015-0383

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local…

Patch available
Fix from $1,600 2015-01-21
Ubuntu Linux HIGH 10.0
CVE-2014-6601EPSS 7%

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via u…

Patch available
Fix from $1,950 2015-01-21
Ubuntu Linux HIGH 7.5
CVE-2014-9604

libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of …

Fix: after 2.5.1
Fix from $1,950 2015-01-16
Ubuntu Linux MEDIUM 5.0
CVE-2015-0222

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to ca…

Fix: after 1.4.17
Fix from $1,600 2015-01-16
Ubuntu Linux HIGH 7.5
CVE-2014-9471EPSS 7%

The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cr…

Fix: 8.23+
Fix from $1,950 2015-01-16
Ubuntu HIGH 7.2
CVE-2014-1949

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass …

Fix: after 3.10.9
Fix from $1,950 2015-01-16
Ubuntu Linux MEDIUM 5.0
CVE-2014-9221

strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Ke…

Mitigation only
Fix from $1,600 2015-01-07
Ubuntu Linux MEDIUM 5.0
CVE-2014-6053EPSS 7%

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a …

Fix: after 0.9.9
Fix from $1,600 2014-12-15
Ubuntu Linux HIGH 7.5
CVE-2014-8504EPSS 6%

Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of ser…

Fix: after 2.24
Fix from $1,950 2014-12-09
Ubuntu Linux HIGH 7.5
CVE-2014-8501EPSS 5%

The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of…

Fix: after 2.24
Fix from $1,950 2014-12-09
Ubuntu Linux MEDIUM 6.4
CVE-2014-7142EPSS 25%

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) I…

Mitigation only
Fix from $1,600 2014-11-26
Ubuntu Linux MEDIUM 5.0
CVE-2014-8768EPSS 20%

Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a deni…

No fix yet
Fix from $1,600 2014-11-20
Ubuntu Linux MEDIUM 5.0
CVE-2014-8483

The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a mal…

Patch available
Fix from $1,600 2014-11-06
Ubuntu Linux HIGH 7.5
CVE-2014-8547

libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-o…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ubuntu Linux HIGH 7.5
CVE-2014-8548

Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly h…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ubuntu Linux HIGH 7.5
CVE-2014-8541

libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an im…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ubuntu Linux HIGH 7.5
CVE-2014-8542

libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial o…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ubuntu Linux HIGH 7.5
CVE-2014-8543

libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote at…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ubuntu Linux HIGH 7.5
CVE-2014-8544

libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ubuntu Linux MEDIUM 5.0
CVE-2014-3660

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dep…

Fix: after 10.10.4
Fix from $1,600 2014-11-04
Ubuntu Linux MEDIUM 5.0
CVE-2014-8080EPSS 6%

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of servic…

Fix: after 1.9.3
Fix from $1,600 2014-11-03
Ubuntu Linux MEDIUM 6.4
CVE-2014-3694

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the B…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
Ubuntu Linux MEDIUM 6.8
CVE-2014-3564

Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remot…

Fix: after 1.5.0
Fix from $1,600 2014-10-20
Ubuntu Linux MEDIUM 6.8
CVE-2014-3686

wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows r…

Mitigation only
Fix from $1,600 2014-10-16
Ubuntu Linux MEDIUM 5.0
CVE-2014-7204

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted Java…

Patch available
Fix from $1,600 2014-10-07