Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2016-2317

Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the…

Mitigation only
Fix from $1,600 2017-02-03
Debian Linux MEDIUM 5.5
CVE-2016-2318

GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) Draw…

Mitigation only
Fix from $1,600 2017-02-03
Debian Linux MEDIUM 5.5
CVE-2016-4570

The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption…

Fix: after 2.7
Fix from $1,600 2017-02-03
Debian Linux MEDIUM 5.5
CVE-2016-4571

The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consum…

Fix: after 2.7
Fix from $1,600 2017-02-03
Debian Linux MEDIUM 5.5
CVE-2016-5241

magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via…

Fix: after 1.3.23
Fix from $1,600 2017-02-03
Debian Linux HIGH 7.5
CVE-2016-9939

Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on th…

Patch available
Fix from $1,950 2017-01-30
Debian Linux MEDIUM 5.3
CVE-2016-2518EPSS 15%

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an add…

Patch available
Fix from $1,600 2017-01-30
Debian Linux CRITICAL 9.8
CVE-2017-5202

The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5203

The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5204EPSS 6%

The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5205

The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux HIGH 7.8
CVE-2016-9453

The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly…

Fix: 4.0.7+
Fix from $1,950 2017-01-27
Debian Linux HIGH 7.5
CVE-2016-10002EPSS 7%

Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, an…

Patch available
Fix from $1,950 2017-01-27
Debian Linux MEDIUM 5.5
CVE-2016-9401

popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.

Fix: 4.4+
Fix from $1,600 2017-01-23
Debian Linux HIGH 7.8
CVE-2015-8971

Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the…

Patch available
Fix from $1,950 2017-01-23
Debian Linux MEDIUM 6.5
CVE-2016-7799

MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Fix: 6.9.6-0 / 7.0.3-2+
Fix from $1,600 2017-01-18
Debian Linux MEDIUM 5.5
CVE-2016-7906

magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.

Patch available
Fix from $1,600 2017-01-18
Debian Linux HIGH 7.5
CVE-2016-9131EPSS 41%

named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (ass…

Fix: after 9.10.3
Fix from $1,950 2017-01-12
Debian Linux HIGH 7.1
CVE-2015-8743

QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'i…

Fix: after 2.5.1
Fix from $1,950 2016-12-29
Debian Linux MEDIUM 6.5
CVE-2016-9914

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 6.5
CVE-2016-9915

Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory cons…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 6.5
CVE-2016-9916

Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consu…

Fix: 2.8.0+
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2015-8744

QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a L…

Fix: after 2.4.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2015-8745

QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Int…

Fix: after 2.4.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2016-1922

QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occu…

Fix: after 2.5.1.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2016-1981

QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data vi…

Fix: after 2.5.1.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2016-2198

QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an applicat…

Fix: after 2.5.1.1
Fix from $1,600 2016-12-29
Debian Linux MEDIUM 5.5
CVE-2016-9776

QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur w…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Debian Linux HIGH 7.8
CVE-2016-8707

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can le…

No fix yet
Fix from $1,950 2016-12-23
Debian Linux HIGH 7.3
CVE-2016-7966

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on t…

Fix: after 4.4.0
Fix from $1,950 2016-12-23