Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.8
CVE-2016-1669

The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to e…

Fix: 0.10.46 / 0.12.15+
Fix from $1,950 2016-05-14
Debian Linux HIGH 8.8
CVE-2016-1667

The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Debian Linux CRITICAL 9.8
CVE-2016-4024EPSS 6%

Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which…

Fix: after 1.4.8
Fix from $2,300 2016-05-13
Debian Linux HIGH 8.2
CVE-2016-3994

The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a …

Fix: after 1.4.8
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2016-3993

Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (ou…

Fix: after 1.4.8
Fix from $1,950 2016-05-13
Debian Linux MEDIUM 6.5
CVE-2016-2860

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intende…

Fix: after 1.6.16
Fix from $1,600 2016-05-13
Debian Linux HIGH 7.8
CVE-2015-8312

Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) vi…

Fix: after 1.6.15
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9771

Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted …

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9764

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9763

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9762

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2011-5326

imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

Fix: after 1.4.8
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2016-2849

Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which migh…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux CRITICAL 9.8
CVE-2016-2195EPSS 7%

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possib…

Fix: after 1.10.10
Fix from $2,300 2016-05-13
Debian Linux HIGH 7.5
CVE-2016-2194

The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspec…

Fix: after 1.10.10
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2015-5727

The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) vi…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2015-5726

The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux HIGH 8.8
CVE-2016-3710

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute ar…

Fix: after 7.0
Fix from $1,950 2016-05-11
Debian Linux MEDIUM 6.1
CVE-2016-1236

Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-depen…

Mitigation only
Fix from $1,600 2016-05-11
Debian Linux MEDIUM 6.1
CVE-2016-4561

Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbit…

Fix: after 3.20160121
Fix from $1,600 2016-05-10
Debian Linux HIGH 8.8
CVE-2016-3105

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

Fix: after 3.7.3
Fix from $1,950 2016-05-09
Debian Linux CRITICAL 9.8
CVE-2016-4422

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux CRITICAL 9.8
CVE-2015-0857EPSS 5%

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux HIGH 7.8
CVE-2015-8325

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_envi…

Fix: after 7.2
Fix from $1,950 2016-05-01
Debian Linux HIGH 8.8
CVE-2016-2806

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to …

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Debian Linux CRITICAL 9.8
CVE-2016-3074EPSS 37%

Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potential…

Fix: 5.5.35 / 5.6.21+
Fix from $2,300 2016-04-26
Debian Linux HIGH 7.5
CVE-2015-8852

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP respo…

Patch available
Fix from $1,950 2016-04-25
Debian Linux MEDIUM 5.9
CVE-2016-4085

Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to …

Mitigation only
Fix from $1,600 2016-04-25
Debian Linux MEDIUM 5.9
CVE-2016-4079

epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which …

Mitigation only
Fix from $1,600 2016-04-25
Debian Linux MEDIUM 5.5
CVE-2016-0648

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.…

Fix: 5.5.49 / 10.0.25+
Fix from $1,600 2016-04-21