Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2016-2385EPSS 31%

Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows r…

Fix: after 4.3.4
Fix from $2,300 2016-04-11
Debian Linux HIGH 8.8
CVE-2016-1235

The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via …

Fix: after 2.5.6
Fix from $1,950 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6700

The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of ser…

Patch available
Fix from $1,950 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6699

The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted respons…

Patch available
Fix from $1,950 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6698

The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted respon…

Patch available
Fix from $1,950 2016-04-11
Debian Linux CRITICAL 9.8
CVE-2016-3153

SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related …

Patch available
Fix from $2,300 2016-04-08
Debian Linux CRITICAL 9.8
CVE-2016-2851EPSS 25%

Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and ap…

Fix: after 4.1.0
Fix from $2,300 2016-04-07
Debian Linux HIGH 7.3
CVE-2016-2098EPSS 81%

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by…

Fix: after 3.2.22.1
Fix from $1,950 2016-04-07
Debian Linux MEDIUM 6.1
CVE-2016-2511

Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path para…

Fix: after 2.3.3
Fix from $1,600 2016-04-07
Debian Linux HIGH 8.1
CVE-2016-2510EPSS 70%

BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to ex…

Patch available
Fix from $1,950 2016-04-07
Debian Linux HIGH 7.3
CVE-2015-8837

Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (a…

Fix: after 20070708
Fix from $1,950 2016-03-30
Debian Linux HIGH 8.8
CVE-2016-1650

The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.26…

Fix: after 49.0.2623.95
Fix from $1,950 2016-03-29
Debian Linux HIGH 8.8
CVE-2016-1649

The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certai…

Fix: after 49.0.2623.95
Fix from $1,950 2016-03-29
Debian Linux HIGH 8.8
CVE-2016-1646 KEVEPSS 48%

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider elem…

Fix: 49.0.2623.108+
Fix from $1,950 2016-03-29
Debian Linux HIGH 8.1
CVE-2016-2342EPSS 12%

The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration…

Mitigation only
Fix from $1,950 2016-03-17
Debian Linux MEDIUM 5.9
CVE-2016-2774EPSS 74%

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attac…

Mitigation only
Fix from $1,600 2016-03-09
Debian Linux MEDIUM 6.3
CVE-2016-0763EPSS 11%

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x befo…

Mitigation only
Fix from $1,600 2016-02-25
Debian Linux MEDIUM 5.3
CVE-2015-5345EPSS 18%

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before con…

No fix yet
Fix from $1,600 2016-02-25
Debian Linux HIGH 7.5
CVE-2013-7448

Directory traversal vulnerability in wiki.c in didiwiki allows remote attackers to read arbitrary files via the page parameter to api/page/get.

Patch available
Fix from $1,950 2016-02-23
Debian Linux MEDIUM 6.5
CVE-2016-2037EPSS 5%

The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted c…

Mitigation only
Fix from $1,600 2016-02-22
Debian Linux MEDIUM 6.8
CVE-2016-2270

Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO p…

Fix: after 4.6.1
Fix from $1,600 2016-02-19
Debian Linux HIGH 8.1
CVE-2015-7547EPSS 90%

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6)…

Patch available
Fix from $1,950 2016-02-18
Debian Linux HIGH 8.8
CVE-2016-1627

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase param…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Debian Linux HIGH 8.8
CVE-2016-1623

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Debian Linux HIGH 8.1
CVE-2016-1526

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before…

Fix: after 38.5.1
Fix from $1,950 2016-02-13
Debian Linux HIGH 8.8
CVE-2016-1521

The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38…

Fix: after 42.0
Fix from $1,950 2016-02-13
Debian Linux MEDIUM 6.5
CVE-2015-8631

Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote aut…

Patch available
Fix from $1,600 2016-02-13
Debian Linux MEDIUM 6.5
CVE-2016-2073

The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML doc…

Fix: 2.9.4+
Fix from $1,600 2016-02-12
Debian Linux HIGH 8.8
CVE-2016-2326

Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service…

Fix: after 2.8.4
Fix from $1,950 2016-02-12
Debian Linux MEDIUM 6.5
CVE-2015-8783

tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.

Fix: 4.0.7+
Fix from $1,600 2016-02-01