Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2016-2318

GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) Draw…

Mitigation only
Fix from $1,600 2017-02-03
Debian Linux HIGH 7.8
CVE-2016-8707

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can le…

No fix yet
Fix from $1,950 2016-12-23
Debian Linux MEDIUM 6.2
CVE-2016-3992

cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$…

Mitigation only
Fix from $1,600 2016-07-26
Debian Linux CRITICAL 9.8
CVE-2016-0749EPSS 8%

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $2,300 2016-06-09
Debian Linux HIGH 8.8
CVE-2016-2335EPSS 10%

The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,950 2016-06-07
Debian Linux HIGH 7.5
CVE-2016-2849

Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which migh…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2015-5727

The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) vi…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2015-5726

The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux MEDIUM 6.1
CVE-2016-1236

Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-depen…

Mitigation only
Fix from $1,600 2016-05-11
Debian Linux CRITICAL 9.8
CVE-2016-4422

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux CRITICAL 9.8
CVE-2015-0857EPSS 5%

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux MEDIUM 5.9
CVE-2016-4085

Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to …

Mitigation only
Fix from $1,600 2016-04-25
Debian Linux MEDIUM 5.9
CVE-2016-4079

epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which …

Mitigation only
Fix from $1,600 2016-04-25
Debian Linux MEDIUM 5.5
CVE-2015-8683

The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a p…

Mitigation only
Fix from $1,600 2016-04-13
Debian Linux HIGH 8.1
CVE-2016-2342EPSS 12%

The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration…

Mitigation only
Fix from $1,950 2016-03-17
Debian Linux MEDIUM 5.9
CVE-2016-2774EPSS 74%

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attac…

Mitigation only
Fix from $1,600 2016-03-09
Debian Linux MEDIUM 6.3
CVE-2016-0763EPSS 11%

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x befo…

Mitigation only
Fix from $1,600 2016-02-25
Debian Linux MEDIUM 5.3
CVE-2015-5345EPSS 18%

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before con…

No fix yet
Fix from $1,600 2016-02-25
Debian Linux MEDIUM 6.5
CVE-2016-2037EPSS 5%

The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted c…

Mitigation only
Fix from $1,600 2016-02-22
Debian Linux MEDIUM 6.4
CVE-2015-8241EPSS 5%

The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (h…

Mitigation only
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 5.0
CVE-2015-7500EPSS 6%

The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap rea…

Mitigation only
Fix from $1,600 2015-12-15
Debian Linux HIGH 7.5
CVE-2015-6525

Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause…

Mitigation only
Fix from $1,950 2015-08-24
Debian Linux MEDIUM 5.0
CVE-2015-6251EPSS 19%

Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long Distinguishe…

Mitigation only
Fix from $1,600 2015-08-24
Debian Linux HIGH 7.5
CVE-2014-6272

Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-depend…

Mitigation only
Fix from $1,950 2015-08-24
Debian Linux HIGH 7.5
CVE-2015-2782EPSS 6%

Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $1,950 2015-04-08
Debian Linux MEDIUM 5.0
CVE-2015-1165

RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket…

Mitigation only
Fix from $1,600 2015-03-09
Debian Linux HIGH 7.1
CVE-2014-9472

The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2015-03-09
Debian Linux MEDIUM 5.0
CVE-2015-2191

Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x be…

Mitigation only
Fix from $1,600 2015-03-08
Debian Linux MEDIUM 6.8
CVE-2014-9667

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to caus…

No fix yet
Fix from $1,600 2015-02-08
Debian Linux MEDIUM 6.8
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server c…

Mitigation only
Fix from $1,600 2014-12-03