Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.0
CVE-2014-9116EPSS 10%

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers …

No fix yet
Fix from $1,600 2014-12-02
Debian Linux MEDIUM 5.0
CVE-2014-9112EPSS 7%

Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block va…

No fix yet
Fix from $1,600 2014-12-02
Debian Linux MEDIUM 5.0
CVE-2014-7815

The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.

Mitigation only
Fix from $1,600 2014-11-14
Debian Linux MEDIUM 6.8
CVE-2014-3160

The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly…

Mitigation only
Fix from $1,600 2014-07-20
Debian Linux MEDIUM 5.0
CVE-2014-3162

Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service or possibly have other impact…

No fix yet
Fix from $1,600 2014-07-20
Debian Linux HIGH 9.3
CVE-2014-2490EPSS 6%

Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, an…

Mitigation only
Fix from $1,950 2014-07-17
Debian Linux MEDIUM 5.0
CVE-2014-4617

The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of…

Mitigation only
Fix from $1,600 2014-06-25
Dpkg Dev MEDIUM 6.4
CVE-2014-3864

Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a …

Mitigation only
Fix from $1,600 2014-05-30
Dpkg Dev MEDIUM 6.4
CVE-2014-3865EPSS 7%

Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended director…

No fix yet
Fix from $1,600 2014-05-30
Dpkg MEDIUM 6.4
CVE-2014-3227

dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames"…

Mitigation only
Fix from $1,600 2014-05-30
Dpkg HIGH 7.1
CVE-2014-3127

dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks…

Mitigation only
Fix from $1,950 2014-05-14
Debian Linux MEDIUM 5.0
CVE-2014-0159

Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service…

Mitigation only
Fix from $1,600 2014-04-14
Debian Linux MEDIUM 5.0
CVE-2013-6890EPSS 9%

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (in…

Mitigation only
Fix from $1,600 2013-12-23
Debian Linux HIGH 7.4
CVE-2013-2072

Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions t…

Mitigation only
Fix from $1,950 2013-08-28
Debian Linux MEDIUM 5.0
CVE-2013-4076

Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remo…

Mitigation only
Fix from $1,600 2013-06-09
Debian Linux MEDIUM 5.0
CVE-2013-4077

Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via …

Mitigation only
Fix from $1,600 2013-06-09
Latd HIGH 10.0
CVE-2013-0251

Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) an…

Mitigation only
Fix from $1,950 2013-03-19
Debian Linux HIGH 7.8
CVE-2013-2487

epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer …

Mitigation only
Fix from $1,950 2013-03-07
Debian Linux MEDIUM 6.1
CVE-2013-2485

The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a…

Mitigation only
Fix from $1,600 2013-03-07
Debian Linux MEDIUM 6.1
CVE-2013-2486

The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark …

Mitigation only
Fix from $1,600 2013-03-07
Debian Linux HIGH 7.1
CVE-2012-3955EPSS 22%

ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circu…

Mitigation only
Fix from $1,950 2012-09-14
Devotee MEDIUM 5.0
CVE-2012-2387

devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers…

Mitigation only
Fix from $1,600 2012-08-20
Debian Linux CRITICAL 9.8
CVE-2012-0507 KEVEPSS 98%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 …

Mitigation only
Fix from $2,300 2012-06-07
Tex Common MEDIUM 6.8
CVE-2011-1400

The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/…

Mitigation only
Fix from $1,600 2011-03-25
Shadow MEDIUM 6.4
CVE-2011-0721

Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via th…

Mitigation only
Fix from $1,600 2011-02-19
Dpkg HIGH 7.2
CVE-2004-2768

dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain…

No fix yet
Fix from $1,950 2010-06-08
Advanced Package Tool HIGH 10.0
CVE-2009-1300

apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones fo…

Mitigation only
Fix from $1,950 2009-04-16
Horde MEDIUM 6.4
CVE-2009-0932EPSS 46%

Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attacke…

Mitigation only
Fix from $1,600 2009-03-17
Shadow HIGH 7.2
CVE-2008-5394

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrar…

No fix yet
Fix from $1,950 2008-12-09
Mailscanner MEDIUM 6.9
CVE-2008-5140

trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack …

Mitigation only
Fix from $1,600 2008-11-18