Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux HIGH 8.8
CVE-2016-3068EPSS 5%

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.

Patch available
Fix from $1,950 2016-04-13
Debian Linux HIGH 8.6
CVE-2015-8702

The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid cha…

Fix: after 2.0.18
Fix from $1,950 2016-04-12
Debian Linux HIGH 7.3
CVE-2016-2098EPSS 81%

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by…

Fix: after 3.2.22.1
Fix from $1,950 2016-04-07
Debian Linux MEDIUM 5.9
CVE-2016-2774EPSS 74%

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attac…

Mitigation only
Fix from $1,600 2016-03-09
Debian Linux MEDIUM 6.8
CVE-2016-2270

Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO p…

Fix: after 4.6.1
Fix from $1,600 2016-02-19
Debian Linux MEDIUM 6.5
CVE-2015-8605EPSS 76%

ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an …

Fix: after 9.353
Fix from $1,600 2016-01-14
Debian Linux MEDIUM 5.4
CVE-2015-5296EPSS 7%

Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in…

Fix: 4.1.22 / 4.2.7+
Fix from $1,600 2015-12-29
Debian Linux MEDIUM 5.0
CVE-2015-8476

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) ema…

Fix: after 5.2.13
Fix from $1,600 2015-12-16
Debian Linux MEDIUM 5.0
CVE-2015-1261

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use…

Fix: after 42.0.2311.107
Fix from $1,600 2015-05-20
Debian Linux MEDIUM 6.8
CVE-2015-2754

FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbo…

Fix: after 1.0.0h
Fix from $1,600 2015-03-31
Debian Linux MEDIUM 6.8
CVE-2015-2753

FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector …

Fix: after 1.0.0h
Fix from $1,600 2015-03-31
Debian Linux MEDIUM 5.0
CVE-2015-0252EPSS 40%

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafte…

Fix: after 3.1.1
Fix from $1,600 2015-03-24
Debian Linux MEDIUM 6.8
CVE-2015-1782

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact vi…

Fix: after 1.4.3
Fix from $1,600 2015-03-13
Debian Linux MEDIUM 5.0
CVE-2015-1382

parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time …

Fix: after 3.0.22
Fix from $1,600 2015-02-03
Debian Linux HIGH 7.5
CVE-2014-6052EPSS 7%

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which a…

Fix: after 0.9.9
Fix from $1,950 2014-12-15
Debian Linux MEDIUM 5.0
CVE-2012-6656

iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via …

Fix: after 2.16
Fix from $1,600 2014-12-05
Debian Linux HIGH 7.1
CVE-2014-9030

The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause…

Patch available
Fix from $1,950 2014-11-24
Debian Linux MEDIUM 5.4
CVE-2014-8594

The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote P…

Patch available
Fix from $1,600 2014-11-19
Debian Linux MEDIUM 5.0
CVE-2014-7815

The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.

Mitigation only
Fix from $1,600 2014-11-14
Advanced Package Tool HIGH 7.5
CVE-2014-0489

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary co…

Patch available
Fix from $1,950 2014-11-03
Advanced Package Tool HIGH 7.5
CVE-2014-0490

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitra…

Fix: after 1.0.8
Fix from $1,950 2014-11-03
Advanced Package Tool MEDIUM 6.8
CVE-2014-0488

APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to h…

Patch available
Fix from $1,600 2014-11-03
Python Imaging MEDIUM 5.0
CVE-2014-3589

PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of se…

Fix: after 2.3.1
Fix from $1,600 2014-08-25
Debian Linux MEDIUM 5.0
CVE-2014-4617

The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of…

Mitigation only
Fix from $1,600 2014-06-25
Debian Linux HIGH 7.5
CVE-2013-6650

The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows…

Fix: after 32.0.1700.101
Fix from $1,950 2014-01-28
Debian Linux MEDIUM 5.2
CVE-2013-4494

Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators …

Fix: after 4.3.4
Fix from $1,600 2013-11-02
Debian Linux MEDIUM 5.0
CVE-2013-2175

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows…

Patch available
Fix from $1,600 2013-08-19
Debian Linux MEDIUM 5.0
CVE-2013-3555

epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrect functions in certain contexts related to cipher…

Patch available
Fix from $1,600 2013-05-25
Debian Linux HIGH 8.8
CVE-2012-0247

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via craf…

Patch available
Fix from $1,950 2012-06-05
Debian Linux HIGH 7.8
CVE-2011-2749EPSS 39%

The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2011-08-15