Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2014-3165

Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web Sockets implementation in Blink, as used in Google…

Fix: after 36.0.1985.142
Fix from $1,950 2014-08-13
Debian Linux MEDIUM 5.0
CVE-2014-4911

The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of servi…

Fix: after 1.2.10
Fix from $1,600 2014-07-22
Debian Linux MEDIUM 6.8
CVE-2014-3160

The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly…

Mitigation only
Fix from $1,600 2014-07-20
Debian Linux MEDIUM 5.0
CVE-2014-3162

Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service or possibly have other impact…

No fix yet
Fix from $1,600 2014-07-20
Debian Linux MEDIUM 5.0
CVE-2014-4342EPSS 7%

MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer d…

Patch available
Fix from $1,600 2014-07-20
Debian Linux HIGH 9.3
CVE-2014-2483EPSS 5%

Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, in…

Patch available
Fix from $1,950 2014-07-17
Debian Linux HIGH 9.3
CVE-2014-2490EPSS 6%

Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, an…

Mitigation only
Fix from $1,950 2014-07-17
Debian Linux MEDIUM 5.0
CVE-2014-4617

The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of…

Mitigation only
Fix from $1,600 2014-06-25
Dpkg Dev MEDIUM 6.4
CVE-2014-3864

Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a …

Mitigation only
Fix from $1,600 2014-05-30
Dpkg Dev MEDIUM 6.4
CVE-2014-3865EPSS 7%

Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended director…

No fix yet
Fix from $1,600 2014-05-30
Dpkg MEDIUM 6.4
CVE-2014-3227

dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames"…

Mitigation only
Fix from $1,600 2014-05-30
Dpkg HIGH 7.1
CVE-2014-3127

dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks…

Mitigation only
Fix from $1,950 2014-05-14
Strongswan MEDIUM 5.0
CVE-2014-2891

strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN…

Fix: after 5.1.2
Fix from $1,600 2014-05-07
Xbuffy MEDIUM 6.8
CVE-2014-0469

Stack-based buffer overflow in a certain Debian patch for xbuffy before 3.3.bl.3.dfsg-9 allows remote attackers to execute arbitrary code via the sub…

Fix: after 3.3.bl.3.dfsg-8
Fix from $1,600 2014-05-05
Dpkg MEDIUM 5.0
CVE-2014-0471

Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote…

Fix: after 1.15.8.8
Fix from $1,600 2014-04-30
Ppthtml MEDIUM 6.8
CVE-2013-4565

Heap-based buffer overflow in the __OLEdecode function in ppthtml 0.5.1 and earlier allows remote attackers to cause a denial of service (crash) and …

Fix: after 0.5.1
Fix from $1,600 2014-04-25
Debian Linux HIGH 7.5
CVE-2014-2709

lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parame…

Fix: after 0.8.8b
Fix from $1,950 2014-04-23
Debian Linux MEDIUM 6.8
CVE-2014-2327

Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users fo…

Fix: after 0.8.8b
Fix from $1,600 2014-04-23
Debian Linux MEDIUM 5.0
CVE-2013-5705

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked…

Fix: 2.7.6+
Fix from $1,600 2014-04-15
Debian Linux MEDIUM 5.0
CVE-2014-0159

Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service…

Mitigation only
Fix from $1,600 2014-04-14
Debian Linux HIGH 7.5
CVE-2014-1609

Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters …

Fix: after 1.2.15
Fix from $1,950 2014-03-20
Debian Linux HIGH 7.5
CVE-2014-1608

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arb…

Fix: after 1.2.15
Fix from $1,950 2014-03-18
Debian Linux CRITICAL 9.8
CVE-2014-2323EPSS 62%

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host nam…

Fix: 1.4.35+
Fix from $2,300 2014-03-14
Debian Linux MEDIUM 5.0
CVE-2014-2324EPSS 29%

Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbi…

Fix: 1.4.35 / 6.5+
Fix from $1,600 2014-03-14
Debian Linux HIGH 7.5
CVE-2013-6650

The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows…

Fix: after 32.0.1700.101
Fix from $1,950 2014-01-28
Debian Linux MEDIUM 5.0
CVE-2013-6424

Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) v…

Fix: 0.31.2+
Fix from $1,600 2014-01-18
Debian Linux MEDIUM 5.0
CVE-2013-6890EPSS 9%

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (in…

Mitigation only
Fix from $1,600 2013-12-23
Debian Linux MEDIUM 6.8
CVE-2013-7020

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which a…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Debian Linux HIGH 9.3
CVE-2013-0858

The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data w…

Fix: after 1.0.3
Fix from $1,950 2013-12-07
Debian Linux HIGH 7.5
CVE-2013-6410

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended acces…

Fix: after 3.4
Fix from $1,950 2013-12-07