Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.8
CVE-2015-1274

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers …

Fix: after 43.0.2357.134
Fix from $1,600 2015-07-23
Debian Linux HIGH 7.5
CVE-2015-1272

Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of serv…

Fix: after 43.0.2357.134
Fix from $1,950 2015-07-23
Debian Linux MEDIUM 6.6
CVE-2015-2594

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 4.0.32, 4.1.40, 4.2.32, and 4.3.30 allow…

Fix: 4.0.32 / 4.1.40+
Fix from $1,600 2015-07-16
Debian Linux MEDIUM 5.0
CVE-2015-3281

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data…

Patch available
Fix from $1,600 2015-07-06
Debian Linux MEDIUM 5.0
CVE-2014-7810EPSS 14%

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider t…

Patch available
Fix from $1,600 2015-06-07
Debian Linux HIGH 7.5
CVE-2015-1265EPSS 8%

Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux MEDIUM 5.0
CVE-2015-1261

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use…

Fix: after 42.0.2311.107
Fix from $1,600 2015-05-20
Debian Linux HIGH 7.5
CVE-2015-1260

Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the WebRTC implementation in Google Chrome before 43.0…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux HIGH 7.5
CVE-2015-1259

PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which allows remote attackers to cause a denial of service…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux HIGH 7.5
CVE-2015-1258

Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to t…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux HIGH 7.5
CVE-2015-1257

platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handl…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux HIGH 7.5
CVE-2015-1256

Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to cause a den…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux MEDIUM 5.0
CVE-2015-1254

core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remot…

Fix: after 42.0.2311.152
Fix from $1,600 2015-05-20
Debian Linux HIGH 7.5
CVE-2015-1253

core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers t…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux HIGH 7.5
CVE-2015-3427

Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers t…

Fix: after 0.12.1
Fix from $1,950 2015-05-14
Debian Linux MEDIUM 5.0
CVE-2015-0971

The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.

Fix: after 2.0.7
Fix from $1,600 2015-05-14
Debian Linux MEDIUM 5.0
CVE-2015-3026

Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointe…

Fix: after 2.4.1
Fix from $1,600 2015-04-29
Debian Linux MEDIUM 6.8
CVE-2015-3417

Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denia…

Fix: after 2.3.5
Fix from $1,600 2015-04-24
Debian Linux HIGH 7.5
CVE-2015-3415

The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attack…

Fix: 5.4.42 / 5.5.26+
Fix from $1,950 2015-04-24
Debian Linux HIGH 7.5
CVE-2015-3333

Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial o…

Fix: after 42.0.2311.60
Fix from $1,950 2015-04-19
Debian Linux HIGH 7.5
CVE-2015-1249

Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 42.0.2311.60
Fix from $1,950 2015-04-19
Debian Linux MEDIUM 5.0
CVE-2015-1246

Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vector…

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Debian Linux MEDIUM 5.0
CVE-2015-1240

gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of …

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Debian Linux MEDIUM 6.5
CVE-2015-1822

chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenti…

Fix: after 1.31
Fix from $1,600 2015-04-16
Debian Linux MEDIUM 6.5
CVE-2015-1821

Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute…

Fix: after 1.31
Fix from $1,600 2015-04-16
Debian Linux HIGH 10.0
CVE-2015-2788

Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecifi…

Fix: after 1.18
Fix from $1,950 2015-04-14
Debian Linux HIGH 7.5
CVE-2015-2782EPSS 6%

Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $1,950 2015-04-08
Debian Linux MEDIUM 6.8
CVE-2015-2754

FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbo…

Fix: after 1.0.0h
Fix from $1,600 2015-03-31
Debian Linux MEDIUM 6.8
CVE-2015-2753

FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector …

Fix: after 1.0.0h
Fix from $1,600 2015-03-31
Debian Linux HIGH 7.5
CVE-2015-0838

Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary c…

Fix: after 0.9.8
Fix from $1,950 2015-03-31