Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2013-3567

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to …

Fix: after 2.8.1
Fix from $1,950 2013-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2013-1872

The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly…

Mitigation only
Fix from $1,600 2013-08-19
Ubuntu Linux HIGH 7.5
CVE-2013-2126

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to ca…

Fix: after 0.15.1
Fix from $1,950 2013-08-14
Ubuntu Linux MEDIUM 5.0
CVE-2013-4124EPSS 69%

Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allo…

Patch available
Fix from $1,600 2013-08-06
Ubuntu Linux HIGH 7.1
CVE-2013-4002EPSS 25%

XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 bef…

Fix: 2.12.0+
Fix from $1,950 2013-07-23
Ubuntu Linux MEDIUM 5.0
CVE-2013-4668

Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remo…

Fix: 3.6.4 / 3.8.3+
Fix from $1,600 2013-07-18
Ubuntu Linux MEDIUM 6.8
CVE-2013-1987

Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow v…

Fix: after 0.9.7
Fix from $1,600 2013-06-15
Ubuntu Linux MEDIUM 6.8
CVE-2013-1981

Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer…

Fix: after 1.5.99.901
Fix from $1,600 2013-06-15
Telepathy Idle MEDIUM 5.8
CVE-2007-6746

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's…

Fix: after 0.1.14.1
Fix from $1,600 2013-05-21
Ubuntu Linux MEDIUM 5.0
CVE-2013-2020

Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewe…

Fix: after 0.97.7
Fix from $1,600 2013-05-13
Ubuntu Linux HIGH 7.5
CVE-2012-6129EPSS 5%

Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a…

Fix: after 2.73
Fix from $1,950 2013-04-03
Ubuntu Linux MEDIUM 6.8
CVE-2013-1865

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remot…

Mitigation only
Fix from $1,600 2013-03-22
Ubuntu Linux HIGH 7.6
CVE-2013-0335

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…

Mitigation only
Fix from $1,950 2013-03-22
Ubuntu Linux HIGH 9.0
CVE-2013-1640

The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pup…

Fix: 1.2.7 / 2.6.18+
Fix from $1,950 2013-03-20
Ubuntu Linux HIGH 7.1
CVE-2013-1653EPSS 5%

Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for inco…

Fix: after 2.6.17
Fix from $1,950 2013-03-20
Ubuntu Linux MEDIUM 5.0
CVE-2013-1654

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between cli…

Mitigation only
Fix from $1,600 2013-03-20
Ubuntu Linux MEDIUM 5.0
CVE-2013-0247

OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a deni…

Fix: after 2013.1.2
Fix from $1,600 2013-02-24
Ubuntu Linux MEDIUM 6.5
CVE-2013-0208

The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from ot…

Patch available
Fix from $1,600 2013-02-13
Ubuntu Linux MEDIUM 5.0
CVE-2013-0189EPSS 23%

cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource con…

Patch available
Fix from $1,600 2013-02-08
Ubuntu Linux CRITICAL 9.8
CVE-2013-0422 KEVEPSS 98%

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantia…

Mitigation only
Fix from $2,300 2013-01-10
Ubuntu Linux HIGH 10.0
CVE-2012-5144

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote att…

Fix: after 23.0.1271.96
Fix from $1,950 2012-12-12
Ubuntu Linux HIGH 7.8
CVE-2012-5688EPSS 11%

ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion fail…

Patch available
Fix from $1,950 2012-12-06
Ubuntu Linux MEDIUM 5.9
CVE-2012-5821

Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof …

No fix yet
Fix from $1,600 2012-11-04
Ubuntu Software Properties MEDIUM 5.8
CVE-2012-5356

The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.8…

Mitigation only
Fix from $1,600 2012-10-10
Ubuntu Linux MEDIUM 5.0
CVE-2012-3509

Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as …

Fix: 2.24+
Fix from $1,600 2012-09-05
Ubuntu Linux MEDIUM 6.1
CVE-2012-3571EPSS 13%

ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) v…

Mitigation only
Fix from $1,600 2012-07-25
Ubuntu Linux HIGH 9.3
CVE-2011-3193EPSS 8%

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows …

Fix: 1.25.1 / 4.7.4+
Fix from $1,950 2012-06-16
Ubuntu Linux MEDIUM 6.5
CVE-2012-0260

The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumpti…

Patch available
Fix from $1,600 2012-06-05
Ubuntu Linux MEDIUM 6.8
CVE-2011-4516EPSS 10%

Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,600 2011-12-15
Ubuntu Linux MEDIUM 6.8
CVE-2011-4517EPSS 10%

The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows…

Mitigation only
Fix from $1,600 2011-12-15