Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux HIGH 7.5
CVE-2017-9524

The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a d…

Fix: after 2.9.1
Fix from $1,950 2017-07-06
Debian Linux HIGH 7.5
CVE-2017-9022

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause …

Fix: after 5.5.2
Fix from $1,950 2017-06-08
Debian Linux MEDIUM 6.5
CVE-2017-9141

In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c becau…

Patch available
Fix from $1,600 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9142

In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing check…

Patch available
Fix from $1,600 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9144

In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.

Patch available
Fix from $1,600 2017-05-22
Debian Linux HIGH 7.8
CVE-2017-8849

smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.

Fix: after 2.0.0
Fix from $1,950 2017-05-17
Debian Linux CRITICAL 9.8
CVE-2016-10243EPSS 7%

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

Patch available
Fix from $2,300 2017-05-02
Debian Linux MEDIUM 5.5
CVE-2017-7613

elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-6498

An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.

Patch available
Fix from $1,600 2017-03-06
Debian Linux MEDIUM 5.5
CVE-2016-9830

The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in …

Patch available
Fix from $1,600 2017-03-01
Debian Linux MEDIUM 5.5
CVE-2017-6188

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting…

Fix: 2.0.30.1 / 2.999.9+
Fix from $1,600 2017-02-22
Debian Linux MEDIUM 6.3
CVE-2016-9955

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses o…

Fix: 1.14.11+
Fix from $1,600 2017-02-17
Debian Linux HIGH 7.5
CVE-2016-9939

Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on th…

Patch available
Fix from $1,950 2017-01-30
Debian Linux HIGH 7.5
CVE-2016-9131EPSS 41%

named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (ass…

Fix: after 9.10.3
Fix from $1,950 2017-01-12
Debian Linux MEDIUM 5.5
CVE-2015-8744

QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a L…

Fix: after 2.4.1
Fix from $1,600 2016-12-29
Debian Linux HIGH 7.8
CVE-2016-1248EPSS 25%

vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of a…

Fix: after 8.0.0055
Fix from $1,950 2016-11-23
Debian Linux HIGH 8.8
CVE-2016-1244EPSS 5%

The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.

Patch available
Fix from $1,950 2016-10-03
Debian Linux HIGH 7.5
CVE-2016-6128EPSS 7%

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attack…

Fix: after 2.2.2
Fix from $1,950 2016-08-07
Debian Linux HIGH 7.8
CVE-2016-4324

Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesh…

Fix: after 5.1.3
Fix from $1,950 2016-07-08
Debian Linux HIGH 7.1
CVE-2016-4449

XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, …

Fix: after 2.9.3
Fix from $1,950 2016-06-09
Debian Linux CRITICAL 9.8
CVE-2014-9746

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in t…

Fix: after 2.5.3
Fix from $2,300 2016-06-07
Debian Linux HIGH 7.5
CVE-2016-4348

The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and a…

Fix: after 2.40.1
Fix from $1,950 2016-05-20
Debian Linux HIGH 7.5
CVE-2015-7558

librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via …

Fix: after 2.40.11
Fix from $1,950 2016-05-20
Debian Linux HIGH 7.5
CVE-2014-9764

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9762

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2016-2194

The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspec…

Fix: after 1.10.10
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2015-5726

The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux MEDIUM 5.9
CVE-2016-4085

Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to …

Mitigation only
Fix from $1,600 2016-04-25
Debian Linux MEDIUM 6.5
CVE-2016-1654

The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a …

Fix: after 49.0.2623.112
Fix from $1,600 2016-04-18
Debian Linux HIGH 8.8
CVE-2016-3069

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.

Patch available
Fix from $1,950 2016-04-13