Vulnerability index

Browse CVEs

245 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2017-13749

There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of servi…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13750

There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial o…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13751

There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service a…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13752

There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service …

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13746

There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial o…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13747

There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service …

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13748

There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of se…

No fix yet
Fix from $1,950 2017-08-29
Fedora MEDIUM 5.5
CVE-2015-5203

Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via …

Mitigation only
Fix from $1,600 2017-08-02
Fedora HIGH 7.5
CVE-2017-1000050

JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one c…

Mitigation only
Fix from $1,950 2017-07-17
Fedora HIGH 7.5
CVE-2016-6342

elog 3.1.1 allows remote attackers to post data as any username in the logbook.

Mitigation only
Fix from $1,950 2017-06-27
Fedora MEDIUM 5.5
CVE-2017-5849

tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service…

No fix yet
Fix from $1,600 2017-03-15
Fedora HIGH 8.1
CVE-2016-9014EPSS 6%

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS …

Mitigation only
Fix from $1,950 2016-12-09
Fedora HIGH 7.5
CVE-2015-2080EPSS 75%

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via i…

No fix yet
Fix from $1,950 2016-10-07
Fedora HIGH 7.5
CVE-2016-2850

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct dow…

Mitigation only
Fix from $1,950 2016-05-13
Fedora HIGH 7.8
CVE-2015-8868

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denia…

Mitigation only
Fix from $1,950 2016-05-06
Fedora CRITICAL 9.8
CVE-2014-9761EPSS 6%

Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of se…

No fix yet
Fix from $2,300 2016-04-19
Fedora HIGH 7.5
CVE-2016-3071

Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

Mitigation only
Fix from $1,950 2016-04-18
Fedora HIGH 7.8
CVE-2015-8106

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2016-04-18
Fedora CRITICAL 9.8
CVE-2016-0729EPSS 9%

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C be…

No fix yet
Fix from $2,300 2016-04-07
Fedora MEDIUM 6.1
CVE-2016-0725

Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2…

Mitigation only
Fix from $1,600 2016-02-22
Fedora MEDIUM 6.1
CVE-2016-1926

Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to injec…

No fix yet
Fix from $1,600 2016-01-26
Fedora MEDIUM 5.0
CVE-2015-6524EPSS 9%

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard o…

Mitigation only
Fix from $1,600 2015-08-24
Fedora MEDIUM 6.8
CVE-2015-4588EPSS 9%

Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly exe…

No fix yet
Fix from $1,600 2015-07-01
Fedora MEDIUM 6.8
CVE-2015-0848EPSS 9%

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cr…

Mitigation only
Fix from $1,600 2015-07-01
Fedora HIGH 7.8
CVE-2015-1868EPSS 82%

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3…

Mitigation only
Fix from $1,950 2015-05-18
Fedora MEDIUM 5.0
CVE-2015-0844

The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1)…

Mitigation only
Fix from $1,600 2015-04-14
Fedora MEDIUM 5.0
CVE-2014-9639

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a W…

No fix yet
Fix from $1,600 2015-01-23
Fedora MEDIUM 5.0
CVE-2014-9638

oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of …

No fix yet
Fix from $1,600 2015-01-23
Fedora MEDIUM 5.8
CVE-2015-1038

p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.

No fix yet
Fix from $1,600 2015-01-21
Fedora MEDIUM 5.0
CVE-2014-9449

Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash…

Mitigation only
Fix from $1,600 2015-01-02