Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Debian Linux MEDIUM 5.9
CVE-2024-20926

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup…

Patch available
Fix from $1,600 2024-01-16
Debian Linux HIGH 7.4
CVE-2024-20918

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo…

Patch available
Fix from $1,950 2024-01-16
Debian Linux MEDIUM 5.5
CVE-2023-51384

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during ad…

Fix: 9.6+
Fix from $1,600 2023-12-18
Debian Linux HIGH 7.5
CVE-2022-21476

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 17.0.2
Fix from $1,950 2022-04-19
Debian Linux MEDIUM 5.3
CVE-2022-21305

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21291

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux HIGH 7.2
CVE-2020-25654

An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication wi…

Fix: 1.1.23 / 2.0.3+
Fix from $1,950 2020-11-24
Xbindkeys Config CRITICAL 9.8
CVE-2014-9513

Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2017-08-28
Debian Linux HIGH 7.5
CVE-2016-6255EPSS 27%

Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registe…

Fix: after 1.6.20
Fix from $1,950 2017-03-07
Debian Linux HIGH 7.5
CVE-2016-9956

The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

Fix: after 2016.4.3
Fix from $1,950 2017-02-22
Debian Linux MEDIUM 6.2
CVE-2016-3992

cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$…

Mitigation only
Fix from $1,600 2016-07-26
Debian Linux MEDIUM 6.5
CVE-2016-2822

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent m…

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Debian Linux MEDIUM 5.3
CVE-2016-1693

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Softw…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Debian Linux HIGH 8.8
CVE-2016-1676

extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allow…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Debian Linux HIGH 8.8
CVE-2016-1667

The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Debian Linux MEDIUM 6.5
CVE-2016-2860

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intende…

Fix: after 1.6.16
Fix from $1,600 2016-05-13
Debian Linux HIGH 8.8
CVE-2016-3105

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

Fix: after 3.7.3
Fix from $1,950 2016-05-09
Debian Linux MEDIUM 5.0
CVE-2014-7810EPSS 14%

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider t…

Patch available
Fix from $1,600 2015-06-07
Debian Linux HIGH 7.5
CVE-2015-1253

core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers t…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux MEDIUM 5.0
CVE-2013-2175

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows…

Patch available
Fix from $1,600 2013-08-19
Debian Linux MEDIUM 5.0
CVE-2012-2351

The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, whic…

Fix: after 1.4.1
Fix from $1,600 2012-07-12