Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2013-2857

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified …

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05
Debian Linux HIGH 7.5
CVE-2013-2858

Use-after-free vulnerability in the HTML5 Audio implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of ser…

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05
Debian Linux HIGH 7.5
CVE-2013-2859

Google Chrome before 27.0.1453.110 allows remote attackers to bypass the Same Origin Policy and trigger namespace pollution via unspecified vectors.

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05
Debian Linux HIGH 7.8
CVE-2013-3561

Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malf…

Patch available
Fix from $1,950 2013-05-25
Debian Linux MEDIUM 5.0
CVE-2013-3559

epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote at…

Patch available
Fix from $1,600 2013-05-25
Debian Linux MEDIUM 5.0
CVE-2013-3560

The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an in…

Patch available
Fix from $1,600 2013-05-25
Debian Linux MEDIUM 5.0
CVE-2013-3562

Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x b…

Patch available
Fix from $1,600 2013-05-25
Debian Linux MEDIUM 5.0
CVE-2013-3555

epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrect functions in certain contexts related to cipher…

Patch available
Fix from $1,600 2013-05-25
Latd HIGH 10.0
CVE-2013-0251

Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) an…

Mitigation only
Fix from $1,950 2013-03-19
Cfingerd HIGH 10.0
CVE-2013-1049

Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execu…

Patch available
Fix from $1,950 2013-03-14
Debian Linux HIGH 7.8
CVE-2013-2487

epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer …

Mitigation only
Fix from $1,950 2013-03-07
Debian Linux MEDIUM 6.1
CVE-2013-2485

The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a…

Mitigation only
Fix from $1,600 2013-03-07
Debian Linux MEDIUM 6.1
CVE-2013-2486

The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark …

Mitigation only
Fix from $1,600 2013-03-07
Debian Linux CRITICAL 9.1
CVE-2012-2239

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity…

Fix: 1.4.4 / 1.5.3+
Fix from $2,300 2012-11-24
Debian Linux MEDIUM 6.8
CVE-2012-4564EPSS 14%

ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and pos…

Fix: after 4.0.3
Fix from $1,600 2012-11-11
Debian Linux HIGH 7.1
CVE-2012-3955EPSS 22%

ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circu…

Mitigation only
Fix from $1,950 2012-09-14
Devotee MEDIUM 5.0
CVE-2012-2387

devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers…

Mitigation only
Fix from $1,600 2012-08-20
Debian Linux MEDIUM 5.0
CVE-2012-2351

The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, whic…

Fix: after 1.4.1
Fix from $1,600 2012-07-12
Debian Linux HIGH 7.5
CVE-2012-1149EPSS 14%

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote att…

Patch available
Fix from $1,950 2012-06-21
Debian Linux CRITICAL 9.8
CVE-2012-0507 KEVEPSS 98%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 …

Mitigation only
Fix from $2,300 2012-06-07
Debian Linux HIGH 7.5
CVE-2012-1610

Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of serv…

Fix: 6.7.6-4+
Fix from $1,950 2012-06-05
Debian Linux MEDIUM 6.5
CVE-2012-1798

The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds…

Patch available
Fix from $1,600 2012-06-05
Debian Linux HIGH 7.8
CVE-2012-1185EPSS 30%

Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial…

Fix: after 6.7.5
Fix from $1,950 2012-06-05
Debian Linux HIGH 7.1
CVE-2012-0920EPSS 6%

Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows …

Fix: after 2012.54
Fix from $1,950 2012-06-05
Debian Linux MEDIUM 5.5
CVE-2012-1186

Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of servi…

Fix: after 6.7.5-8
Fix from $1,600 2012-06-05
Debian Linux MEDIUM 6.5
CVE-2012-0259

The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a ze…

Fix: 6.7.6-3+
Fix from $1,600 2012-06-05
Debian Linux MEDIUM 5.5
CVE-2012-0248

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains …

Patch available
Fix from $1,600 2012-06-05
Debian Linux HIGH 8.8
CVE-2012-0247

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via craf…

Patch available
Fix from $1,950 2012-06-05
Debian Linux MEDIUM 5.0
CVE-2011-4361

MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive in…

Fix: 1.17.1+
Fix from $1,600 2012-01-08
Debian Linux MEDIUM 5.0
CVE-2011-4360

MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or…

Fix: 1.17.1+
Fix from $1,600 2012-01-08