Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Adequate MEDIUM 6.2
CVE-2013-6409

Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOC…

Fix: after 0.8
Fix from $1,600 2013-12-07
Debian Linux HIGH 7.6
CVE-2013-4559EPSS 11%

lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run a…

Fix: 1.4.33+
Fix from $1,950 2013-11-20
Debian Linux MEDIUM 5.0
CVE-2013-4560EPSS 5%

Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspec…

Fix: 1.4.33+
Fix from $1,600 2013-11-20
Debian Linux HIGH 7.5
CVE-2013-4508

lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting …

Fix: after 1.4.33
Fix from $1,950 2013-11-08
Debian Linux MEDIUM 5.2
CVE-2013-4494

Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators …

Fix: after 4.3.4
Fix from $1,600 2013-11-02
Debian Linux HIGH 7.5
CVE-2013-4391EPSS 5%

Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash…

Fix: 190+
Fix from $1,950 2013-10-28
Debian Linux MEDIUM 5.9
CVE-2013-4394

The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XK…

Fix: 194+
Fix from $1,600 2013-10-28
Debian Linux MEDIUM 6.8
CVE-2013-2927

Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrom…

Fix: after 30.0.1599.100
Fix from $1,600 2013-10-16
Debian Linux MEDIUM 6.9
CVE-2013-4327

systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by lev…

Fix: after 207
Fix from $1,600 2013-10-03
Debian Linux MEDIUM 6.8
CVE-2013-4234

Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier all…

Fix: after 0.8.8.4
Fix from $1,600 2013-09-16
Debian Linux MEDIUM 6.8
CVE-2013-4233

Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service…

Fix: after 0.8.8.4
Fix from $1,600 2013-09-16
Debian Linux MEDIUM 6.8
CVE-2013-4232EPSS 5%

Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,600 2013-09-10
Debian Linux MEDIUM 6.8
CVE-2013-4243EPSS 7%

Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial o…

Fix: after 4.0.3
Fix from $1,600 2013-09-10
Debian Linux HIGH 7.5
CVE-2013-5589

SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parame…

Fix: after 0.8.8b
Fix from $1,950 2013-08-29
Debian Linux HIGH 7.4
CVE-2013-2072

Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions t…

Mitigation only
Fix from $1,950 2013-08-28
Debian Linux HIGH 7.5
CVE-2013-2900

The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname compo…

Fix: after 29.0.1547.56
Fix from $1,950 2013-08-21
Debian Linux HIGH 7.5
CVE-2013-2901

Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Renderer11.cpp in Almost Native Graphics Layer Engine (…

Fix: after 29.0.1547.56
Fix from $1,950 2013-08-21
Debian Linux MEDIUM 5.0
CVE-2013-2905

The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which …

Fix: after 29.0.1547.56
Fix from $1,600 2013-08-21
Debian Linux MEDIUM 6.8
CVE-2013-4852

Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of ser…

Fix: after 5.1.5
Fix from $1,600 2013-08-19
Debian Linux MEDIUM 5.0
CVE-2013-2175

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows…

Patch available
Fix from $1,600 2013-08-19
Debian Linux HIGH 7.5
CVE-2013-2886

Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.95 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 28.0.1500.94
Fix from $1,950 2013-07-31
Debian Linux HIGH 7.5
CVE-2013-2885

Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 28.0.1500.94
Fix from $1,950 2013-07-31
Debian Linux MEDIUM 5.0
CVE-2013-2876

browser/extensions/api/tabs/tabs_api.cc in Google Chrome before 28.0.1500.71 does not properly enforce restrictions on the capture of screenshots by …

Fix: after 28.0.1500.70
Fix from $1,600 2013-07-10
Debian Linux HIGH 7.5
CVE-2013-2873

Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 28.0.1500.70
Fix from $1,950 2013-07-10
Debian Linux MEDIUM 5.0
CVE-2013-2868

common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certa…

Fix: after 28.0.1500.70
Fix from $1,600 2013-07-10
Debian Linux MEDIUM 6.8
CVE-2013-2064

Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors rela…

Fix: after 1.9
Fix from $1,600 2013-06-15
Debian Linux MEDIUM 5.0
CVE-2013-4076

Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remo…

Mitigation only
Fix from $1,600 2013-06-09
Debian Linux MEDIUM 5.0
CVE-2013-4077

Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via …

Mitigation only
Fix from $1,600 2013-06-09
Debian Linux HIGH 7.5
CVE-2013-2860

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified …

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05
Debian Linux HIGH 7.5
CVE-2013-2861

Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or …

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05