Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2014-8096

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-se…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8095

The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authent…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8094

Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1…

Patch available
Fix from $1,600 2014-12-10
Debian Linux HIGH 7.5
CVE-2014-8990EPSS 5%

default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.

Fix: after 2.1.5
Fix from $1,950 2014-12-05
Debian Linux MEDIUM 5.0
CVE-2012-6656

iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via …

Fix: after 2.16
Fix from $1,600 2014-12-05
Debian Linux HIGH 7.5
CVE-2014-9157EPSS 6%

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format st…

Fix: 2.42.4+
Fix from $1,950 2014-12-03
Debian Linux MEDIUM 6.8
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server c…

Mitigation only
Fix from $1,600 2014-12-03
Debian Linux MEDIUM 5.0
CVE-2014-9116EPSS 10%

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers …

No fix yet
Fix from $1,600 2014-12-02
Debian Linux MEDIUM 5.0
CVE-2014-9112EPSS 7%

Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block va…

No fix yet
Fix from $1,600 2014-12-02
Debian Linux HIGH 7.5
CVE-2014-9087EPSS 5%

Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (cr…

Fix: 1.3.2+
Fix from $1,950 2014-12-01
Debian Linux HIGH 7.5
CVE-2014-9089

Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands vi…

Fix: after 1.2.17
Fix from $1,950 2014-11-28
Debian Linux MEDIUM 6.1
CVE-2010-5312EPSS 18%

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arb…

Fix: 1.10.0 / 7.86+
Fix from $1,600 2014-11-24
Debian Linux HIGH 7.1
CVE-2014-9030

The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause…

Patch available
Fix from $1,950 2014-11-24
Debian Linux MEDIUM 5.4
CVE-2014-8594

The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote P…

Patch available
Fix from $1,600 2014-11-19
Debian Linux MEDIUM 5.0
CVE-2014-7815

The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.

Mitigation only
Fix from $1,600 2014-11-14
Debian Linux HIGH 7.2
CVE-2014-3689

The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecifie…

Fix: after 2.1.3
Fix from $1,950 2014-11-14
Advanced Package Tool HIGH 7.5
CVE-2014-0487

APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified i…

Patch available
Fix from $1,950 2014-11-03
Advanced Package Tool HIGH 7.5
CVE-2014-0489

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary co…

Patch available
Fix from $1,950 2014-11-03
Advanced Package Tool HIGH 7.5
CVE-2014-0490

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitra…

Fix: after 1.0.8
Fix from $1,950 2014-11-03
Advanced Package Tool MEDIUM 6.8
CVE-2014-0488

APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to h…

Patch available
Fix from $1,600 2014-11-03
Debian Linux MEDIUM 5.0
CVE-2014-1829

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected requ…

Fix: after 2.2.1
Fix from $1,600 2014-10-15
Debian Linux MEDIUM 5.8
CVE-2014-7155

The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which al…

Fix: after 4.4.0
Fix from $1,600 2014-10-02
Advanced Package Tool MEDIUM 6.8
CVE-2014-6273

Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash…

Fix: after 1.0.1
Fix from $1,600 2014-09-30
Debian Linux HIGH 7.5
CVE-2014-5119EPSS 18%

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a de…

Fix: 2.20+
Fix from $1,950 2014-08-29
Debian Linux HIGH 7.5
CVE-2014-3169

Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows r…

Fix: after 37.0.2062.93
Fix from $1,950 2014-08-27
Python Imaging MEDIUM 5.0
CVE-2014-3589

PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of se…

Fix: after 2.3.1
Fix from $1,600 2014-08-25
Kde4libs MEDIUM 6.9
CVE-2014-5033

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypas…

Fix: after 5.0
Fix from $1,600 2014-08-19
Debian Linux MEDIUM 6.8
CVE-2014-5204

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce ar…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
Debian Linux HIGH 7.8
CVE-2014-4344EPSS 7%

The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 a…

Patch available
Fix from $1,950 2014-08-14
Debian Linux HIGH 7.6
CVE-2014-4343EPSS 6%

Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1…

Patch available
Fix from $1,950 2014-08-14