Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 8.8
CVE-2008-2934

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary cod…

No fix yet
Fix from $1,950 2008-07-18
Ubuntu Linux HIGH 9.3
CVE-2008-2712EPSS 15%

Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitiz…

Fix: after 7.1.314
Fix from $1,950 2008-06-16
Ubuntu Linux HIGH 7.5
CVE-2008-1105EPSS 69%

Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary …

Fix: after 3.0.29
Fix from $1,950 2008-05-29
Ubuntu Linux HIGH 9.3
CVE-2008-0888EPSS 6%

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to caus…

Fix: 6.0 / 10.6.3+
Fix from $1,950 2008-03-17
Ubuntu Linux HIGH 9.3
CVE-2008-1195EPSS 6%

Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_1…

Mitigation only
Fix from $1,950 2008-03-06
Ubuntu Linux HIGH 9.3
CVE-2007-6427

The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping…

Fix: 1.4.1 / 10.4.11+
Fix from $1,950 2008-01-18
Ubuntu Linux MEDIUM 6.8
CVE-2007-4829

Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files…

Fix: after 1.36
Fix from $1,600 2007-11-02
Ubuntu Linux HIGH 7.8
CVE-2007-4988

Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a cr…

Fix: 6.3.5-9+
Fix from $1,950 2007-09-24
Ubuntu Linux CRITICAL 9.8
CVE-2007-3798EPSS 70%

Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs …

Fix: 5.5 / 6.1+
Fix from $2,300 2007-07-16
Ubuntu Linux MEDIUM 6.8
CVE-2007-2949EPSS 7%

Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code vi…

Fix: after 2.2.15
Fix from $1,600 2007-07-04
Ubuntu Linux HIGH 9.0
CVE-2007-2798EPSS 8%

Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authent…

Fix: after 1.6.1
Fix from $1,950 2007-06-26
Ubuntu Linux HIGH 9.0
CVE-2007-1216EPSS 10%

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 be…

Fix: 1.6.1+
Fix from $1,950 2007-04-06
Ubuntu Linux HIGH 9.3
CVE-2006-6143EPSS 8%

The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that u…

Patch available
Fix from $1,950 2006-12-31
Ubuntu Linux MEDIUM 6.5
CVE-2006-6811EPSS 10%

KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) s…

No fix yet
Fix from $1,600 2006-12-29
Ubuntu Linux HIGH 7.5
CVE-2006-5779EPSS 76%

OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which trig…

Fix: 2.3.29+
Fix from $1,950 2006-11-07
Ubuntu Linux HIGH 7.5
CVE-2006-4095EPSS 12%

BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an a…

Fix: 10.3.9 / 10.4.9+
Fix from $1,950 2006-09-06
Ubuntu Linux HIGH 7.5
CVE-2006-2275

Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver …

Fix: 2.6.17+
Fix from $1,950 2006-05-09
Ubuntu Linux HIGH 7.6
CVE-2005-4808

Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-a…

Fix: 2.17+
Fix from $1,950 2005-12-31
Ubuntu Linux HIGH 7.5
CVE-2005-4807EPSS 12%

Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 200507…

Fix: 2.17+
Fix from $1,950 2005-12-31
Ubuntu Linux MEDIUM 5.0
CVE-2005-1527

Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl…

Fix: after 6.4
Fix from $1,600 2005-08-15
Ubuntu Linux MEDIUM 5.0
CVE-2005-1260EPSS 6%

bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "dec…

Fix: 1.0.3 / 10.4.11+
Fix from $1,600 2005-05-19
Ubuntu Linux CRITICAL 9.8
CVE-2005-1513EPSS 11%

Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote a…

No fix yet
Fix from $2,300 2005-05-11
Ubuntu Linux HIGH 7.5
CVE-2004-1002

Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an inval…

Mitigation only
Fix from $1,950 2005-03-01
Ubuntu Linux CRITICAL 9.8
CVE-2004-2154

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name …

Fix: 1.1.21+
Fix from $2,300 2004-12-31