Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
MEDIUM 6.8 CVE-2015-8036 Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial o… Debian Linux 1.3.14 / 2.1.2+ Fix from $1,6002015-11-02 MEDIUM 6.8 CVE-2015-6031 Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers… Debian Linux after 1.9 Fix from $1,6002015-11-02 MEDIUM 6.8 CVE-2015-5291 Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote … Debian Linux 1.2.17 / 1.3.14+ Fix from $1,6002015-11-02 MEDIUM 6.8 CVE-2015-1781EPSS 5% Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-depen… Debian Linux after 2.21 Fix from $1,6002015-09-28 MEDIUM 5.0 CVE-2015-3281 The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data… Debian Linux Patch available Fix from $1,6002015-07-06 HIGH 7.5 CVE-2015-1257 platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handl… Debian Linux after 42.0.2311.152 Fix from $1,9502015-05-20 MEDIUM 5.0 CVE-2015-1246 Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vector… Debian Linux after 42.0.2311.60 Fix from $1,6002015-04-19 MEDIUM 5.0 CVE-2015-1240 gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of … Debian Linux after 42.0.2311.60 Fix from $1,6002015-04-19 MEDIUM 6.5 CVE-2015-1821 Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute… Debian Linux after 1.31 Fix from $1,6002015-04-16 HIGH 10.0 CVE-2015-2788 Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecifi… Debian Linux after 1.18 Fix from $1,9502015-04-14 HIGH 7.5 CVE-2015-2782EPSS 6% Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code v… Debian Linux Mitigation only Fix from $1,9502015-04-08 HIGH 7.5 CVE-2015-0838 Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary c… Debian Linux after 0.9.8 Fix from $1,9502015-03-31 HIGH 10.0 CVE-2014-2830EPSS 6% Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecifi… Cifs Utils after 6.3 Fix from $1,9502015-03-31 MEDIUM 5.8 CVE-2014-9672 Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bo… Debian Linux after 2.5.3 Fix from $1,6002015-02-08 MEDIUM 6.8 CVE-2014-9667 sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to caus… Debian Linux No fix yet Fix from $1,6002015-02-08 HIGH 7.5 CVE-2014-9663EPSS 5% The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely cal… Debian Linux Patch available Fix from $1,9502015-02-08 HIGH 7.5 CVE-2014-9662 cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a deni… Debian Linux after 2.5.3 Fix from $1,9502015-02-08 MEDIUM 6.8 CVE-2014-8158EPSS 14% Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or poss… Debian Linux after 1.900.1 Fix from $1,6002015-01-26 HIGH 7.5 CVE-2014-8145EPSS 8% Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV f… Debian Linux after 14.4.1 Fix from $1,9502014-12-31 MEDIUM 6.5 CVE-2014-8102 The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver … Debian Linux after 1.16.2.99.901 Fix from $1,6002014-12-10 MEDIUM 6.5 CVE-2014-8098EPSS 5% The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows r… Debian Linux after 1.16.2.99.901 Fix from $1,6002014-12-10 MEDIUM 6.5 CVE-2014-8096 The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-se… Debian Linux after 1.16.2.99.901 Fix from $1,6002014-12-10 MEDIUM 6.5 CVE-2014-8095 The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authent… Debian Linux after 1.16.2.99.901 Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-9116EPSS 10% The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers … Debian Linux No fix yet Fix from $1,6002014-12-02 MEDIUM 5.0 CVE-2014-9112EPSS 7% Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block va… Debian Linux No fix yet Fix from $1,6002014-12-02 MEDIUM 6.8 CVE-2014-6273 Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash… Advanced Package Tool after 1.0.1 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2014-4342EPSS 7% MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer d… Debian Linux Patch available Fix from $1,6002014-07-20 MEDIUM 6.8 CVE-2014-0469 Stack-based buffer overflow in a certain Debian patch for xbuffy before 3.3.bl.3.dfsg-9 allows remote attackers to execute arbitrary code via the sub… Xbuffy after 3.3.bl.3.dfsg-8 Fix from $1,6002014-05-05 MEDIUM 6.8 CVE-2013-4565 Heap-based buffer overflow in the __OLEdecode function in ppthtml 0.5.1 and earlier allows remote attackers to cause a denial of service (crash) and … Ppthtml after 0.5.1 Fix from $1,6002014-04-25 MEDIUM 5.0 CVE-2014-0159 Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service… Debian Linux Mitigation only Fix from $1,6002014-04-14