Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.0
CVE-2011-4539EPSS 15%

dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote a…

Mitigation only
Fix from $1,600 2011-12-08
Ubuntu Linux CRITICAL 9.8
CVE-2011-3544 KEVEPSS 97%

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrust…

Fix: 1.6.0+
Fix from $2,300 2011-10-19
Ubuntu Linux HIGH 7.8
CVE-2011-2748EPSS 39%

The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2011-08-15
Ubuntu Linux MEDIUM 6.5
CVE-2011-0730

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed…

Fix: 2.0.2 / 2.0.3+
Fix from $1,600 2011-06-02
Ubuntu Linux HIGH 7.5
CVE-2010-3069EPSS 11%

Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of s…

Fix: 3.4.9 / 3.5.5+
Fix from $1,950 2010-09-15
Ubuntu Linux MEDIUM 6.8
CVE-2010-1781

Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a…

Fix: 4.1+
Fix from $1,600 2010-09-09
Ubuntu Linux MEDIUM 6.8
CVE-2010-1812

Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to e…

Fix: 1.2.6 / 4.1+
Fix from $1,600 2010-09-09
Ubuntu Linux MEDIUM 6.8
CVE-2010-1814

WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a…

Fix: 1.2.6 / 4.1+
Fix from $1,600 2010-09-09
Ubuntu Linux MEDIUM 6.8
CVE-2010-1815

Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to e…

Fix: 1.2.6 / 4.1+
Fix from $1,600 2010-09-09
Ubuntu Linux MEDIUM 6.8
CVE-2010-2806EPSS 6%

Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service …

Fix: 2.4.2 / 4.1.0+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2807

FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (applicati…

Fix: 2.4.2 / 4.1.0+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2808

Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service…

Fix: 2.4.2 / 4.1.0+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2498EPSS 6%

The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remo…

Fix: 2.4.0 / 10.6.5+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2499EPSS 6%

Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service…

Fix: 2.4.0 / 10.6.5+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2500

Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (…

Fix: 2.4.0 / 10.6.5+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2519EPSS 6%

Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial…

Fix: 2.4.0 / 10.6.5+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2541

Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application c…

Fix: 2.4.2+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2805EPSS 5%

The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote…

Fix: 2.4.2 / 4.1.0+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 5.1
CVE-2010-2520EPSS 6%

Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows…

Fix: 2.4.0 / 10.6.5+
Fix from $1,600 2010-08-19
Ubuntu Linux MEDIUM 6.8
CVE-2010-2067

Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a deni…

Fix: 3.9.4+
Fix from $1,600 2010-06-24
Ubuntu Linux HIGH 7.5
CVE-2010-2063EPSS 79%

Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remot…

Fix: after 3.3.12
Fix from $1,950 2010-06-17
Ubuntu Linux HIGH 9.3
CVE-2010-0395EPSS 10%

OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Pyth…

Fix: 3.2.1+
Fix from $1,950 2010-06-10
Ubuntu Linux MEDIUM 5.0
CVE-2010-1624EPSS 6%

The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a de…

Fix: 2.7.0+
Fix from $1,600 2010-05-14
Ubuntu Linux CRITICAL 9.8
CVE-2010-0840 KEVEPSS 96%

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 …

Patch available
Fix from $2,300 2010-04-01
Ubuntu Linux MEDIUM 5.0
CVE-2009-2797

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from…

Fix: 3.1 / 3.1.1+
Fix from $1,600 2009-09-10
Ubuntu Linux MEDIUM 5.8
CVE-2009-2474

neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) fiel…

Fix: 0.28.6 / 10.6.5+
Fix from $1,600 2009-08-21
Ubuntu Linux HIGH 7.5
CVE-2009-0949EPSS 20%

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote …

Fix: 1.3.10 / 10.4.11+
Fix from $1,950 2009-06-09
Ubuntu Linux HIGH 7.5
CVE-2009-0586EPSS 6%

Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugin…

Fix: 0.10.23+
Fix from $1,950 2009-03-14
Ubuntu Linux HIGH 7.2
CVE-2008-4539

Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local us…

Fix: 0.10.0+
Fix from $1,950 2008-12-29
Ubuntu Linux HIGH 9.3
CVE-2008-4063

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and a…

Fix: after 3.0.1
Fix from $1,950 2008-09-24