Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2016-9907

Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB…

Fix: after 2.7.1
Fix from $1,600 2016-12-23
Debian Linux MEDIUM 6.5
CVE-2016-9911

Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data …

Fix: after 2.7.1
Fix from $1,600 2016-12-23
Debian Linux MEDIUM 6.5
CVE-2016-9921

Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA …

Fix: after 2.7.1
Fix from $1,600 2016-12-23
Debian Linux CRITICAL 9.8
CVE-2013-1430

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd …

Fix: after 0.8.0
Fix from $2,300 2016-12-16
Debian Linux MEDIUM 6.5
CVE-2016-9964

redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-C…

Patch available
Fix from $1,600 2016-12-16
Debian Linux MEDIUM 5.3
CVE-2016-6313

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 mak…

Fix: after 1.5.3
Fix from $1,600 2016-12-13
Debian Linux CRITICAL 9.8
CVE-2016-9427

Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) an…

Fix: after 7.4.4
Fix from $2,300 2016-12-12
Debian Linux MEDIUM 6.0
CVE-2016-7116

Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the …

Fix: after 2.6.2
Fix from $1,600 2016-12-10
Debian Linux MEDIUM 6.0
CVE-2016-6836

The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host m…

Fix: after 2.7.1
Fix from $1,600 2016-12-10
Debian Linux HIGH 7.1
CVE-2016-5424

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users…

Fix: after 9.1.22
Fix from $1,950 2016-12-09
Debian Linux HIGH 8.3
CVE-2016-5423EPSS 6%

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to ca…

Fix: after 9.1.22
Fix from $1,950 2016-12-09
Debian Linux MEDIUM 6.0
CVE-2016-9106

Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service…

Fix: after 2.7.1
Fix from $1,600 2016-12-09
Debian Linux MEDIUM 6.0
CVE-2016-9105

Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service …

Fix: after 2.7.1
Fix from $1,600 2016-12-09
Debian Linux MEDIUM 6.0
CVE-2016-9103

The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory …

Fix: after 2.7.1
Fix from $1,600 2016-12-09
Debian Linux MEDIUM 6.0
CVE-2016-9102

Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of s…

Fix: after 2.7.1
Fix from $1,600 2016-12-09
Debian Linux MEDIUM 6.0
CVE-2016-9101

Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption a…

Fix: after 2.7.1
Fix from $1,600 2016-12-09
Debian Linux HIGH 7.8
CVE-2016-1248EPSS 25%

vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of a…

Fix: after 8.0.0055
Fix from $1,950 2016-11-23
Debian Linux MEDIUM 6.0
CVE-2016-8910

The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of servic…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 6.0
CVE-2016-8909

The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (i…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 6.0
CVE-2016-8667

The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-b…

Fix: after 2.8.1.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 6.0
CVE-2016-8578

The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of ser…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux MEDIUM 6.0
CVE-2016-8577

Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service …

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Debian Linux CRITICAL 9.8
CVE-2016-7117EPSS 24%

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbit…

Fix: 3.2.80 / 3.4.113+
Fix from $2,300 2016-10-10
Debian Linux MEDIUM 5.5
CVE-2016-7424

The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL po…

Fix: after 11.7
Fix from $1,600 2016-10-07
Debian Linux CRITICAL 9.8
CVE-2016-7161EPSS 6%

Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code …

Fix: after 2.6.2
Fix from $2,300 2016-10-05
Debian Linux HIGH 7.5
CVE-2016-1246

Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors re…

Fix: after 4.036
Fix from $1,950 2016-10-05
Debian Linux HIGH 8.8
CVE-2016-1244EPSS 5%

The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.

Patch available
Fix from $1,950 2016-10-03
Debian Linux CRITICAL 9.8
CVE-2016-1243EPSS 5%

Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname.

Patch available
Fix from $2,300 2016-10-03
Debian Linux CRITICAL 9.8
CVE-2016-5180EPSS 9%

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of…

Fix: 0.10.48 / 0.12.17+
Fix from $2,300 2016-10-03
Debian Linux HIGH 7.5
CVE-2016-7045

The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corrupti…

Fix: after 0.8.19
Fix from $1,950 2016-09-27