Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2016-7044

The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers t…

Fix: after 0.8.19
Fix from $1,950 2016-09-27
Debian Linux MEDIUM 5.9
CVE-2016-7142

The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof ce…

Fix: after 2.0.22
Fix from $1,600 2016-09-26
Debian Linux CRITICAL 9.8
CVE-2016-4303EPSS 7%

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (cra…

Fix: 3.0.12 / 3.1.3+
Fix from $2,300 2016-09-26
Debian Linux HIGH 8.8
CVE-2016-4738

libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a …

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Debian Linux CRITICAL 9.8
CVE-2016-6525

Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (cra…

Fix: after 1.9
Fix from $2,300 2016-09-22
Debian Linux HIGH 7.8
CVE-2016-7163EPSS 7%

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, w…

Patch available
Fix from $1,950 2016-09-21
Debian Linux HIGH 8.1
CVE-2016-7143

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently …

Fix: after 3.5.2
Fix from $1,950 2016-09-21
Debian Linux CRITICAL 9.8
CVE-2016-6354EPSS 9%

Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of servi…

Fix: after 2.6.0
Fix from $2,300 2016-09-21
Debian Linux CRITICAL 9.8
CVE-2015-8871

Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact v…

Fix: after 2.1.0
Fix from $2,300 2016-09-21
Debian Linux HIGH 7.5
CVE-2015-8917

bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character …

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Debian Linux MEDIUM 5.9
CVE-2016-7180

epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant…

Patch available
Fix from $1,600 2016-09-09
Debian Linux MEDIUM 5.9
CVE-2016-7179

Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remot…

Patch available
Fix from $1,600 2016-09-09
Debian Linux MEDIUM 5.9
CVE-2016-7177

epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, w…

Patch available
Fix from $1,600 2016-09-09
Debian Linux HIGH 7.8
CVE-2016-6318

Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (applicatio…

Fix: 2.9.6+
Fix from $1,950 2016-09-07
Debian Linux CRITICAL 9.1
CVE-2016-6254EPSS 6%

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a…

Fix: 5.4.3 / 5.5.2+
Fix from $2,300 2016-08-19
Debian Linux CRITICAL 9.8
CVE-2015-8949

Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call …

Patch available
Fix from $2,300 2016-08-19
Debian Linux CRITICAL 9.8
CVE-2014-9906EPSS 6%

Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary c…

Fix: after 4.028
Fix from $2,300 2016-08-19
Debian Linux MEDIUM 6.5
CVE-2016-6214

gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted …

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Debian Linux MEDIUM 6.5
CVE-2016-6207EPSS 6%

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers …

Fix: 5.5.38 / 5.6.24+
Fix from $1,600 2016-08-12
Debian Linux MEDIUM 6.5
CVE-2016-6161

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) …

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Debian Linux MEDIUM 6.5
CVE-2016-6132

The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of…

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Debian Linux HIGH 7.5
CVE-2016-5420EPSS 15%

curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to h…

Fix: after 7.50.0
Fix from $1,950 2016-08-10
Debian Linux HIGH 7.5
CVE-2016-5419EPSS 16%

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass…

Fix: after 7.50.0
Fix from $1,950 2016-08-10
Debian Linux HIGH 7.5
CVE-2016-6128EPSS 7%

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attack…

Fix: after 2.2.2
Fix from $1,950 2016-08-07
Debian Linux CRITICAL 9.1
CVE-2016-5116

gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers …

Fix: after 2.2.1
Fix from $2,300 2016-08-07
Debian Linux HIGH 7.8
CVE-2016-3070

The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate…

Fix: after 4.3.6
Fix from $1,950 2016-08-06
Debian Linux HIGH 7.8
CVE-2016-3822

exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08…

Patch available
Fix from $1,950 2016-08-05
Debian Linux MEDIUM 6.1
CVE-2016-6186EPSS 6%

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.…

Fix: after 1.8.13
Fix from $1,600 2016-08-05
Debian Linux HIGH 7.8
CVE-2016-1238

(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/…

Fix: 3.4.2+
Fix from $1,950 2016-08-02
Debian Linux MEDIUM 6.2
CVE-2016-3992

cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$…

Mitigation only
Fix from $1,600 2016-07-26