Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2016-4324

Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesh…

Fix: after 5.1.3
Fix from $1,950 2016-07-08
Debian Linux HIGH 7.8
CVE-2016-5829

Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local …

Fix: 3.2.82 / 3.10.103+
Fix from $1,950 2016-06-27
Debian Linux MEDIUM 6.3
CVE-2016-5728

Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local use…

Fix: after 4.6
Fix from $1,600 2016-06-27
Debian Linux HIGH 8.8
CVE-2016-3062

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (mem…

Fix: after 11.6
Fix from $1,950 2016-06-16
Debian Linux HIGH 7.5
CVE-2016-4478

Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a …

Fix: after 7.2.6
Fix from $1,950 2016-06-13
Debian Linux MEDIUM 6.5
CVE-2016-2822

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent m…

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Debian Linux HIGH 7.1
CVE-2016-4449

XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, …

Fix: after 2.9.3
Fix from $1,950 2016-06-09
Debian Linux CRITICAL 9.8
CVE-2016-0749EPSS 8%

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $2,300 2016-06-09
Debian Linux CRITICAL 9.8
CVE-2016-5108EPSS 25%

Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause …

Fix: after 2.2.3
Fix from $2,300 2016-06-08
Debian Linux HIGH 8.8
CVE-2016-2335EPSS 10%

The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,950 2016-06-07
Debian Linux CRITICAL 9.8
CVE-2015-7695

The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL c…

Fix: after 1.12.15
Fix from $2,300 2016-06-07
Debian Linux HIGH 7.8
CVE-2015-5723

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x b…

Fix: after 2.4.7
Fix from $1,950 2016-06-07
Debian Linux HIGH 7.5
CVE-2014-9747

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode,…

Fix: after 2.5.3
Fix from $1,950 2016-06-07
Debian Linux CRITICAL 9.8
CVE-2014-9746

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in t…

Fix: after 2.5.3
Fix from $2,300 2016-06-07
Debian Linux HIGH 7.5
CVE-2016-1700

extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of ext…

Fix: after 51.0.2704.63
Fix from $1,950 2016-06-05
Debian Linux MEDIUM 6.5
CVE-2016-1698

The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not val…

Fix: after 51.0.2704.63
Fix from $1,600 2016-06-05
Debian Linux MEDIUM 5.3
CVE-2016-1693

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Softw…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Debian Linux HIGH 7.5
CVE-2016-1690

The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Debian Linux MEDIUM 6.5
CVE-2016-1687

The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Debian Linux HIGH 8.8
CVE-2016-1681

Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, all…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Debian Linux HIGH 8.8
CVE-2016-1676

extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allow…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Debian Linux HIGH 8.8
CVE-2016-1674

The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Debian Linux HIGH 7.5
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate ran…

Fix: after 2.3.36
Fix from $1,950 2016-06-01
Debian Linux HIGH 7.8
CVE-2015-8875

Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops…

Fix: after 2.33
Fix from $1,950 2016-06-01
Debian Linux MEDIUM 5.5
CVE-2015-8558

The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU c…

Fix: after 2.5.1.1
Fix from $1,600 2016-05-23
Debian Linux HIGH 7.5
CVE-2016-4348

The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and a…

Fix: after 2.40.1
Fix from $1,950 2016-05-20
Debian Linux HIGH 7.5
CVE-2015-7558

librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via …

Fix: after 2.40.11
Fix from $1,950 2016-05-20
Debian Linux HIGH 7.8
CVE-2016-1840

Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tv…

Patch available
Fix from $1,950 2016-05-20
Debian Linux MEDIUM 5.5
CVE-2016-1833

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2…

Patch available
Fix from $1,600 2016-05-20
Debian Linux HIGH 7.5
CVE-2016-3627EPSS 7%

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a d…

Patch available
Fix from $1,950 2016-05-17