Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 9.3
CVE-2014-0455EPSS 6%

Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and …

Fix: 4.0.0.3 / 8.0.1.1+
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-0451

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, …

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-0452

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-0454

Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and …

Fix: 4.0.0.3 / 8.0.1.1+
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-0458

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux MEDIUM 5.8
CVE-2014-0460

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers…

Fix: 15.1+
Fix from $1,600 2014-04-16
Ubuntu Linux HIGH 7.5
CVE-2014-0446EPSS 6%

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, …

Mitigation only
Fix from $1,950 2014-04-16
Ubuntu Linux HIGH 10.0
CVE-2014-0429EPSS 8%

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers…

Fix: 4.0.0.3 / 8.0.1.1+
Fix from $1,950 2014-04-16
Libpam Modules MEDIUM 6.9
CVE-2011-3628

Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu…

Mitigation only
Fix from $1,600 2014-04-15
Ubuntu Linux MEDIUM 6.8
CVE-2014-2241

The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a sub…

Fix: after 2.5.2
Fix from $1,600 2014-03-18
Ubuntu Linux MEDIUM 6.8
CVE-2013-6473

Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via…

Patch available
Fix from $1,600 2014-03-14
Ubuntu Linux MEDIUM 6.8
CVE-2013-6474

Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a cra…

Fix: after 1.0.46
Fix from $1,600 2014-03-14
Ubuntu Linux MEDIUM 6.8
CVE-2013-6475

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow …

Fix: after 1.0.46
Fix from $1,600 2014-03-14
Ubuntu Linux MEDIUM 5.0
CVE-2013-4496EPSS 11%

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, …

Fix: 3.6.23 / 4.0.16+
Fix from $1,600 2014-03-14
Ubuntu Linux MEDIUM 6.9
CVE-2014-0004

Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute …

Fix: after 1.0.4
Fix from $1,600 2014-03-11
Ubuntu Linux MEDIUM 6.8
CVE-2013-6393EPSS 7%

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denia…

Fix: after 0.1.4
Fix from $1,600 2014-02-06
Ubuntu Linux MEDIUM 5.0
CVE-2014-1483

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by usi…

Fix: 2.24 / 27.0+
Fix from $1,600 2014-02-06
Ubuntu Linux MEDIUM 6.8
CVE-2011-2725

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot…

Fix: after 4.7.4
Fix from $1,600 2014-02-04
Ubuntu Linux MEDIUM 6.8
CVE-2013-0339

libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExt…

Fix: after 2.9.1
Fix from $1,600 2014-01-21
Ubuntu Linux MEDIUM 5.0
CVE-2013-6425

Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependen…

Patch available
Fix from $1,600 2014-01-18
Ubuntu Linux MEDIUM 5.8
CVE-2013-6391

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when on…

Fix: 2013.2.1+
Fix from $1,600 2013-12-14
Ubuntu Linux MEDIUM 5.8
CVE-2013-1058

maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via…

Fix: after 12.04.4
Fix from $1,600 2013-11-23
Ubuntu Linux HIGH 7.5
CVE-2013-4473EPSS 7%

Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial o…

Fix: after 0.24.1
Fix from $1,950 2013-11-23
Ubuntu Linux MEDIUM 5.0
CVE-2010-3443

ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple C…

Fix: after 0.6.2
Fix from $1,600 2013-11-23
Ubuntu Linux MEDIUM 5.0
CVE-2013-4474EPSS 10%

Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial o…

Fix: after 0.24.1
Fix from $1,600 2013-11-23
Ubuntu Linux MEDIUM 5.0
CVE-2013-4402EPSS 5%

The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recu…

Mitigation only
Fix from $1,600 2013-10-28
Ubuntu Linux HIGH 7.2
CVE-2013-4288

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pke…

Fix: 0.112.1+
Fix from $1,950 2013-10-03
Ubuntu Linux HIGH 7.1
CVE-2013-5745EPSS 9%

The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, …

Fix: after 3.7.3
Fix from $1,950 2013-10-01
Ubuntu Linux MEDIUM 5.0
CVE-2013-0211

Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64…

Fix: after 3.1.2
Fix from $1,600 2013-09-30
Ubuntu Linux MEDIUM 5.0
CVE-2013-4130

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly p…

Fix: after 0.12.3
Fix from $1,600 2013-08-20