Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2015-8782

tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CV…

Fix: 4.0.7+
Fix from $1,600 2016-02-01
Debian Linux MEDIUM 6.5
CVE-2015-8781

tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compres…

Fix: 4.0.7+
Fix from $1,600 2016-02-01
Fuse HIGH 7.8
CVE-2016-1233

An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world…

Fix: after 2.9.3-14
Fix from $1,950 2016-01-26
Debian Linux HIGH 7.7
CVE-2015-7974EPSS 6%

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remot…

Fix: 4.2.8 / 4.3.90+
Fix from $1,950 2016-01-26
Debian Linux MEDIUM 6.5
CVE-2015-8605EPSS 76%

ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an …

Fix: after 9.353
Fix from $1,600 2016-01-14
Debian Linux HIGH 7.5
CVE-2015-8467

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x befor…

Fix: 4.1.22 / 4.2.7+
Fix from $1,950 2015-12-29
Debian Linux MEDIUM 5.3
CVE-2015-5299EPSS 14%

The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before…

Fix: 4.1.22 / 4.2.7+
Fix from $1,600 2015-12-29
Debian Linux MEDIUM 5.4
CVE-2015-5296EPSS 7%

Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in…

Fix: 4.1.22 / 4.2.7+
Fix from $1,600 2015-12-29
Debian Linux MEDIUM 5.0
CVE-2015-8476

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) ema…

Fix: after 5.2.13
Fix from $1,600 2015-12-16
Debian Linux MEDIUM 5.0
CVE-2015-8317EPSS 6%

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterm…

Fix: after 2.9.2
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 6.4
CVE-2015-8241EPSS 5%

The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (h…

Mitigation only
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 5.0
CVE-2015-7500EPSS 6%

The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap rea…

Mitigation only
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 5.0
CVE-2015-7497EPSS 7%

Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a den…

Fix: after 2.9.2
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 6.8
CVE-2015-7984

Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition …

Fix: 5.2.8 / 5.2.11+
Fix from $1,600 2015-11-19
Debian Linux MEDIUM 6.8
CVE-2015-7942

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, whi…

Fix: after 10.11.3
Fix from $1,600 2015-11-18
Debian Linux HIGH 7.1
CVE-2015-2696

lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a…

Fix: 1.14+
Fix from $1,950 2015-11-09
Debian Linux MEDIUM 5.0
CVE-2015-7762

rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowl…

Fix: after 1.6.14.1
Fix from $1,600 2015-11-06
Debian Linux HIGH 7.5
CVE-2015-6855

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or p…

Fix: after 2.4.1
Fix from $1,950 2015-11-06
Debian Linux MEDIUM 6.8
CVE-2015-8036

Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial o…

Fix: 1.3.14 / 2.1.2+
Fix from $1,600 2015-11-02
Debian Linux MEDIUM 6.8
CVE-2015-6031

Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers…

Fix: after 1.9
Fix from $1,600 2015-11-02
Debian Linux MEDIUM 6.8
CVE-2015-5291

Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote …

Fix: 1.2.17 / 1.3.14+
Fix from $1,600 2015-11-02
Debian Linux MEDIUM 5.0
CVE-2015-4896

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.0.34, 4.1.42, 4.2.34, 4.3.32, and 5.0.8,…

Fix: 4.0.34 / 4.1.42+
Fix from $1,600 2015-10-21
Debian Linux MEDIUM 6.8
CVE-2015-1781EPSS 5%

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-depen…

Fix: after 2.21
Fix from $1,600 2015-09-28
Debian Linux MEDIUM 5.0
CVE-2014-9745

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "br…

Fix: after 2.5.2
Fix from $1,600 2015-09-14
Debian Linux HIGH 7.5
CVE-2015-6525

Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause…

Mitigation only
Fix from $1,950 2015-08-24
Debian Linux MEDIUM 5.0
CVE-2015-6496

conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote at…

Fix: after 1.4.2
Fix from $1,600 2015-08-24
Debian Linux MEDIUM 5.0
CVE-2015-6251EPSS 19%

Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long Distinguishe…

Mitigation only
Fix from $1,600 2015-08-24
Debian Linux HIGH 7.5
CVE-2014-6272

Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-depend…

Mitigation only
Fix from $1,950 2015-08-24
Debian Linux MEDIUM 5.0
CVE-2015-1819EPSS 6%

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expa…

Fix: after 9.2.1
Fix from $1,600 2015-08-14
Debian Linux MEDIUM 5.0
CVE-2015-3225EPSS 8%

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to …

Fix: after 1.5.3
Fix from $1,600 2015-07-26