Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2014-9116EPSS 10% The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers … Debian Linux No fix yet Fix from $1,6002014-12-02 MEDIUM 5.0 CVE-2014-9112EPSS 7% Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block va… Debian Linux No fix yet Fix from $1,6002014-12-02 MEDIUM 5.0 CVE-2014-7815 The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value. Debian Linux Mitigation only Fix from $1,6002014-11-14 MEDIUM 6.8 CVE-2014-3160 The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly… Debian Linux Mitigation only Fix from $1,6002014-07-20 MEDIUM 5.0 CVE-2014-3162 Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service or possibly have other impact… Debian Linux No fix yet Fix from $1,6002014-07-20 HIGH 9.3 CVE-2014-2490EPSS 6% Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, an… Debian Linux Mitigation only Fix from $1,9502014-07-17 MEDIUM 5.0 CVE-2014-4617 The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of… Debian Linux Mitigation only Fix from $1,6002014-06-25 MEDIUM 6.4 CVE-2014-3864 Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a … Dpkg Dev Mitigation only Fix from $1,6002014-05-30 MEDIUM 6.4 CVE-2014-3865EPSS 7% Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended director… Dpkg Dev No fix yet Fix from $1,6002014-05-30 MEDIUM 6.4 CVE-2014-3227 dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames"… Dpkg Mitigation only Fix from $1,6002014-05-30 HIGH 7.1 CVE-2014-3127 dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks… Dpkg Mitigation only Fix from $1,9502014-05-14 MEDIUM 5.0 CVE-2014-0159 Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service… Debian Linux Mitigation only Fix from $1,6002014-04-14 MEDIUM 5.0 CVE-2013-6890EPSS 9% denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (in… Debian Linux Mitigation only Fix from $1,6002013-12-23 HIGH 7.4 CVE-2013-2072 Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions t… Debian Linux Mitigation only Fix from $1,9502013-08-28 MEDIUM 5.0 CVE-2013-4076 Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remo… Debian Linux Mitigation only Fix from $1,6002013-06-09 MEDIUM 5.0 CVE-2013-4077 Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via … Debian Linux Mitigation only Fix from $1,6002013-06-09 HIGH 10.0 CVE-2013-0251 Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) an… Latd Mitigation only Fix from $1,9502013-03-19 HIGH 7.8 CVE-2013-2487 epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer … Debian Linux Mitigation only Fix from $1,9502013-03-07 MEDIUM 6.1 CVE-2013-2485 The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a… Debian Linux Mitigation only Fix from $1,6002013-03-07 MEDIUM 6.1 CVE-2013-2486 The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark … Debian Linux Mitigation only Fix from $1,6002013-03-07 HIGH 7.1 CVE-2012-3955EPSS 22% ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circu… Debian Linux Mitigation only Fix from $1,9502012-09-14 MEDIUM 5.0 CVE-2012-2387 devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers… Devotee Mitigation only Fix from $1,6002012-08-20 CRITICAL 9.8 CVE-2012-0507 KEVEPSS 98% Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 … Debian Linux Mitigation only Fix from $2,3002012-06-07 MEDIUM 6.8 CVE-2011-1400 The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/… Tex Common Mitigation only Fix from $1,6002011-03-25 MEDIUM 6.4 CVE-2011-0721 Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via th… Shadow Mitigation only Fix from $1,6002011-02-19 HIGH 7.2 CVE-2004-2768 dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain… Dpkg No fix yet Fix from $1,9502010-06-08 HIGH 10.0 CVE-2009-1300 apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones fo… Advanced Package Tool Mitigation only Fix from $1,9502009-04-16 MEDIUM 6.4 CVE-2009-0932EPSS 46% Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attacke… Horde Mitigation only Fix from $1,6002009-03-17 HIGH 7.2 CVE-2008-5394 /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrar… Shadow No fix yet Fix from $1,9502008-12-09 MEDIUM 6.9 CVE-2008-5140 trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack … Mailscanner Mitigation only Fix from $1,6002008-11-18