Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2014-9706

The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a director…

Fix: after 0.9.8
Fix from $1,950 2015-03-31
Cifs Utils HIGH 10.0
CVE-2014-2830EPSS 6%

Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecifi…

Fix: after 6.3
Fix from $1,950 2015-03-31
Debian Linux HIGH 7.5
CVE-2015-2155EPSS 8%

The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspec…

Fix: after 4.7.0
Fix from $1,950 2015-03-24
Debian Linux MEDIUM 5.0
CVE-2015-0252EPSS 40%

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafte…

Fix: after 3.1.1
Fix from $1,600 2015-03-24
Debian Linux MEDIUM 6.8
CVE-2015-1782

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact vi…

Fix: after 1.4.3
Fix from $1,600 2015-03-13
Debian Linux MEDIUM 5.0
CVE-2015-1165

RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket…

Mitigation only
Fix from $1,600 2015-03-09
Debian Linux HIGH 7.1
CVE-2014-9472

The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2015-03-09
Debian Linux MEDIUM 5.0
CVE-2015-2191

Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x be…

Mitigation only
Fix from $1,600 2015-03-08
Debian Linux MEDIUM 5.0
CVE-2015-0885

checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

Fix: after 1.02
Fix from $1,600 2015-02-28
Debian Linux HIGH 7.5
CVE-2015-1592EPSS 75%

Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw funct…

Fix: 5.2.12 / 6.0.7+
Fix from $1,950 2015-02-19
Debian Linux MEDIUM 5.8
CVE-2014-9672

Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bo…

Fix: after 2.5.3
Fix from $1,600 2015-02-08
Debian Linux MEDIUM 6.8
CVE-2014-9667

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to caus…

No fix yet
Fix from $1,600 2015-02-08
Debian Linux HIGH 7.5
CVE-2014-9663EPSS 5%

The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely cal…

Patch available
Fix from $1,950 2015-02-08
Debian Linux HIGH 7.5
CVE-2014-9662

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a deni…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Debian Linux MEDIUM 5.0
CVE-2015-1382

parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time …

Fix: after 3.0.22
Fix from $1,600 2015-02-03
Debian Linux MEDIUM 5.0
CVE-2015-1381

Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or me…

Fix: after 3.0.22
Fix from $1,600 2015-02-03
Debian Linux MEDIUM 6.8
CVE-2014-8158EPSS 14%

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or poss…

Fix: after 1.900.1
Fix from $1,600 2015-01-26
Debian Linux HIGH 7.5
CVE-2014-8157EPSS 17%

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or po…

Fix: after 1.900.1
Fix from $1,950 2015-01-26
Dpkg MEDIUM 6.8
CVE-2014-8625

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial…

Fix: after 1.17.21
Fix from $1,600 2015-01-20
Debian Linux MEDIUM 5.4
CVE-2014-9271

Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web scr…

Patch available
Fix from $1,600 2015-01-09
Mime Support HIGH 7.5
CVE-2014-7209

run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metach…

Fix: after 3.52-1
Fix from $1,950 2015-01-06
Debian Linux HIGH 7.5
CVE-2014-8145EPSS 8%

Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV f…

Fix: after 14.4.1
Fix from $1,950 2014-12-31
Debian Linux MEDIUM 5.0
CVE-2014-8132EPSS 5%

Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denia…

Patch available
Fix from $1,600 2014-12-29
Debian Linux MEDIUM 5.0
CVE-2014-9323

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer…

Fix: 2.1.7+
Fix from $1,600 2014-12-16
Debian Linux HIGH 7.5
CVE-2014-9057

SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers t…

Fix: after 5.17
Fix from $1,950 2014-12-16
Debian Linux HIGH 7.6
CVE-2013-6435EPSS 8%

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the con…

Fix: after 4.11.1
Fix from $1,950 2014-12-16
Debian Linux HIGH 7.5
CVE-2014-6052EPSS 7%

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which a…

Fix: after 0.9.9
Fix from $1,950 2014-12-15
Debian Linux MEDIUM 5.0
CVE-2014-8601EPSS 69%

PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradati…

Fix: after 3.6.1
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8102

The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver …

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8098EPSS 5%

The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows r…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10