Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2016-0647

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.…

Fix: 5.5.49 / 10.0.25+
Fix from $1,600 2016-04-21
Debian Linux MEDIUM 5.5
CVE-2016-0646

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.…

Fix: 5.5.48 / 10.0.24+
Fix from $1,600 2016-04-21
Debian Linux MEDIUM 5.5
CVE-2016-0644

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.…

Fix: 5.5.48 / 10.0.24+
Fix from $1,600 2016-04-21
Debian Linux MEDIUM 5.1
CVE-2016-0641

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.…

Fix: 10.0.24 / 10.1.12+
Fix from $1,600 2016-04-21
Debian Linux CRITICAL 9.8
CVE-2016-1659

Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 49.0.2623.112
Fix from $2,300 2016-04-18
Debian Linux HIGH 8.8
CVE-2016-1655

Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to…

Fix: after 49.0.2623.112
Fix from $1,950 2016-04-18
Debian Linux MEDIUM 6.5
CVE-2016-1654

The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a …

Fix: after 49.0.2623.112
Fix from $1,600 2016-04-18
Debian Linux HIGH 8.8
CVE-2016-1653

The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cau…

Fix: after 49.0.2623.112
Fix from $1,950 2016-04-18
Debian Linux MEDIUM 6.1
CVE-2016-1652

Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions su…

Fix: after 49.0.2623.112
Fix from $1,600 2016-04-18
Debian Linux MEDIUM 6.5
CVE-2015-8784

The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image,…

Fix: 4.0.7+
Fix from $1,600 2016-04-13
Debian Linux MEDIUM 5.5
CVE-2015-8683

The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a p…

Mitigation only
Fix from $1,600 2016-04-13
Debian Linux MEDIUM 6.5
CVE-2015-1547

The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIF…

Fix: after 4.0.6
Fix from $1,600 2016-04-13
Debian Linux MEDIUM 6.5
CVE-2014-9655

The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a de…

Fix: after 4.0.6
Fix from $1,600 2016-04-13
Debian Linux HIGH 8.8
CVE-2016-3982

Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bo…

Fix: after 0.7.5
Fix from $1,950 2016-04-13
Debian Linux HIGH 8.8
CVE-2016-3069

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.

Patch available
Fix from $1,950 2016-04-13
Debian Linux HIGH 8.8
CVE-2016-3068EPSS 5%

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.

Patch available
Fix from $1,950 2016-04-13
Debian Linux MEDIUM 6.1
CVE-2016-2228

Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edi…

Fix: after 5.2.11
Fix from $1,600 2016-04-13
Debian Linux MEDIUM 5.4
CVE-2016-2058

Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary…

Patch available
Fix from $1,600 2016-04-13
Debian Linux HIGH 8.8
CVE-2016-2056EPSS 55%

xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the …

Patch available
Fix from $1,950 2016-04-13
Debian Linux HIGH 7.5
CVE-2016-2055EPSS 18%

xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration director…

Patch available
Fix from $1,950 2016-04-13
Debian Linux CRITICAL 9.8
CVE-2016-2054EPSS 6%

Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary cod…

Patch available
Fix from $2,300 2016-04-13
Debian Linux MEDIUM 5.3
CVE-2016-3170

The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensi…

Patch available
Fix from $1,600 2016-04-12
Debian Linux HIGH 8.1
CVE-2016-3169

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code tha…

Patch available
Fix from $1,950 2016-04-12
Debian Linux MEDIUM 5.9
CVE-2016-3166

CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to…

Patch available
Fix from $1,600 2016-04-12
Debian Linux HIGH 7.5
CVE-2016-3163

The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large…

Patch available
Fix from $1,950 2016-04-12
Debian Linux HIGH 8.6
CVE-2015-8702

The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid cha…

Fix: after 2.0.18
Fix from $1,950 2016-04-12
Debian Linux MEDIUM 5.3
CVE-2015-8537

app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive info…

Fix: after 2.6.8
Fix from $1,600 2016-04-12
Debian Linux HIGH 7.4
CVE-2015-8474

Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, …

Fix: after 2.6.6
Fix from $1,950 2016-04-12
Debian Linux MEDIUM 5.3
CVE-2015-8346

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive info…

Fix: after 2.6.7
Fix from $1,600 2016-04-12
Debian Linux CRITICAL 9.8
CVE-2015-8710

The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds h…

Fix: 2.9.3+
Fix from $2,300 2016-04-11