Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2014-9706
The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a director…
Debian Linux
after 0.9.8
HIGH 10.0
CVE-2014-2830EPSS 6%
Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecifi…
Cifs Utils
after 6.3
HIGH 7.5
CVE-2015-2155EPSS 8%
The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspec…
Debian Linux
after 4.7.0
MEDIUM 5.0
CVE-2015-0252EPSS 40%
internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafte…
Debian Linux
after 3.1.1
MEDIUM 6.8
CVE-2015-1782
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact vi…
Debian Linux
after 1.4.3
MEDIUM 5.0
CVE-2015-1165
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket…
Debian Linux
Mitigation only
HIGH 7.1
CVE-2014-9472
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of se…
Debian Linux
Mitigation only
MEDIUM 5.0
CVE-2015-2191
Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x be…
Debian Linux
Mitigation only
MEDIUM 5.0
CVE-2015-0885
checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.
Debian Linux
after 1.02
HIGH 7.5
CVE-2015-1592EPSS 75%
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw funct…
Debian Linux
5.2.12 / 6.0.7+
MEDIUM 5.8
CVE-2014-9672
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bo…
Debian Linux
after 2.5.3
MEDIUM 6.8
CVE-2014-9667
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to caus…
Debian Linux
No fix yet
HIGH 7.5
CVE-2014-9663EPSS 5%
The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely cal…
Debian Linux
Patch available
HIGH 7.5
CVE-2014-9662
cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a deni…
Debian Linux
after 2.5.3
MEDIUM 5.0
CVE-2015-1382
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time …
Debian Linux
after 3.0.22
MEDIUM 5.0
CVE-2015-1381
Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or me…
Debian Linux
after 3.0.22
MEDIUM 6.8
CVE-2014-8158EPSS 14%
Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or poss…
Debian Linux
after 1.900.1
HIGH 7.5
CVE-2014-8157EPSS 17%
Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or po…
Debian Linux
after 1.900.1
MEDIUM 6.8
CVE-2014-8625
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial…
Dpkg
after 1.17.21
MEDIUM 5.4
CVE-2014-9271
Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web scr…
Debian Linux
Patch available
HIGH 7.5
CVE-2014-7209
run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metach…
Mime Support
after 3.52-1
HIGH 7.5
CVE-2014-8145EPSS 8%
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV f…
Debian Linux
after 14.4.1
MEDIUM 5.0
CVE-2014-8132EPSS 5%
Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denia…
Debian Linux
Patch available
MEDIUM 5.0
CVE-2014-9323
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer…
Debian Linux
2.1.7+
HIGH 7.5
CVE-2014-9057
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers t…
Debian Linux
after 5.17
HIGH 7.6
CVE-2013-6435EPSS 8%
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the con…
Debian Linux
after 4.11.1
HIGH 7.5
CVE-2014-6052EPSS 7%
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which a…
Debian Linux
after 0.9.9
MEDIUM 5.0
CVE-2014-8601EPSS 69%
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradati…
Debian Linux
after 3.6.1
MEDIUM 6.5
CVE-2014-8102
The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver …
Debian Linux
after 1.16.2.99.901
MEDIUM 6.5
CVE-2014-8098EPSS 5%
The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows r…
Debian Linux
after 1.16.2.99.901