Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.0
CVE-2014-3565

snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via …

Fix: after 5.7.0
Fix from $1,600 2014-10-07
Ubuntu Linux MEDIUM 5.8
CVE-2014-3633

The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image,…

Fix: after 1.2.8
Fix from $1,600 2014-10-06
Acpi Support HIGH 7.2
CVE-2014-0484

The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment."

No fix yet
Fix from $1,950 2014-09-22
Ubuntu Linux HIGH 7.5
CVE-2014-3618EPSS 9%

Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute…

No fix yet
Fix from $1,950 2014-09-08
Ubuntu Linux MEDIUM 5.0
CVE-2014-5461EPSS 12%

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of servic…

Patch available
Fix from $1,600 2014-09-04
Reportbug MEDIUM 6.8
CVE-2014-0479

reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versio…

Fix: after 6.5.0
Fix from $1,600 2014-08-06
Ubuntu Linux HIGH 7.9
CVE-2014-3560EPSS 56%

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspec…

Mitigation only
Fix from $1,950 2014-08-06
Ubuntu Linux MEDIUM 6.8
CVE-2014-4909EPSS 5%

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial o…

Fix: after 2.83
Fix from $1,600 2014-07-29
Ubuntu Linux MEDIUM 5.0
CVE-2014-5031

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive in…

Fix: after 1.7.4
Fix from $1,600 2014-07-29
Acpi Support MEDIUM 6.9
CVE-2014-1419

Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vecto…

Fix: after 0.141
Fix from $1,600 2014-07-24
Ubuntu Linux HIGH 7.6
CVE-2013-6433

The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which a…

Fix: after 2013.2.3
Fix from $1,950 2014-06-02
Ubuntu Linux MEDIUM 5.0
CVE-2014-3925

sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext…

Fix: after 1.7
Fix from $1,600 2014-06-01
Ltsp Display Manager HIGH 10.0
CVE-2012-1166

The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETU…

Mitigation only
Fix from $1,950 2014-05-21
Ubuntu Linux HIGH 7.5
CVE-2014-0210

Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a craft…

Fix: after 1.4.7
Fix from $1,950 2014-05-15
Ubuntu Linux HIGH 7.5
CVE-2014-0211

Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4…

Fix: after 1.4.7
Fix from $1,950 2014-05-15
Ubuntu Linux HIGH 10.0
CVE-2014-1528EPSS 6%

The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers …

Mitigation only
Fix from $1,950 2014-04-30
Ubuntu Linux HIGH 9.0
CVE-2014-0187

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass secu…

Mitigation only
Fix from $1,950 2014-04-28
Update Manager MEDIUM 6.4
CVE-2011-3152

DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x b…

Fix: after 1
Fix from $1,600 2014-04-27
Ubuntu Linux HIGH 10.0
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x befor…

Fix: after 1.4.10
Fix from $1,950 2014-04-23
Ubuntu Linux HIGH 10.0
CVE-2014-2421EPSS 7%

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect con…

Fix: 4.0.0.3 / 8.0.1.1+
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-2412

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, SE 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentialit…

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-2414

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-2423

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-2427

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, …

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 9.3
CVE-2014-0461EPSS 6%

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…

Fix: 4.0.0.3 / 8.0.1.1+
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 9.3
CVE-2014-2397EPSS 6%

Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and …

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-2402

Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and …

No fix yet
Fix from $1,950 2014-04-16
Ubuntu Linux MEDIUM 5.0
CVE-2014-2403

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via vecto…

Mitigation only
Fix from $1,600 2014-04-16
Ubuntu Linux HIGH 10.0
CVE-2014-0456EPSS 7%

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…

Fix: 4.0.0.3 / 8.0.1.1+
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 10.0
CVE-2014-0457EPSS 7%

Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attack…

Fix: 4.0.0.3 / 8.0.1.1+
Fix from $1,950 2014-04-16