Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.8
CVE-2015-6816

ganglia-web before 3.7.1 allows remote attackers to bypass authentication.

Fix: after 3.7.0
Fix from $2,300 2017-08-09
Fedora MEDIUM 6.5
CVE-2017-11368

In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requ…

Patch available
Fix from $1,600 2017-08-09
Fedora MEDIUM 5.5
CVE-2015-5203

Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via …

Mitigation only
Fix from $1,600 2017-08-02
Fedora MEDIUM 5.5
CVE-2015-5221

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote…

Fix: after 1.900.1
Fix from $1,600 2017-07-25
Fedora HIGH 7.5
CVE-2015-5194EPSS 6%

The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via …

Patch available
Fix from $1,950 2017-07-21
Fedora HIGH 7.5
CVE-2015-5195EPSS 7%

ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or …

Fix: after 4.2.7
Fix from $1,950 2017-07-21
Fedora HIGH 7.5
CVE-2015-5219EPSS 6%

The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows re…

Patch available
Fix from $1,950 2017-07-21
Fedora HIGH 7.5
CVE-2015-5300EPSS 9%

The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by de…

Patch available
Fix from $1,950 2017-07-21
Fedora HIGH 7.5
CVE-2017-1000050

JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one c…

Mitigation only
Fix from $1,950 2017-07-17
Fedmsg HIGH 7.5
CVE-2017-1000001

FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.

Fix: after 0.18.1
Fix from $1,950 2017-07-17
Fedora HIGH 7.5
CVE-2016-6342

elog 3.1.1 allows remote attackers to post data as any username in the logbook.

Mitigation only
Fix from $1,950 2017-06-27
Arm Installer HIGH 7.0
CVE-2017-7496

fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount ope…

Fix: after 1.99.16
Fix from $1,950 2017-06-26
Fedora HIGH 7.5
CVE-2016-3704

Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.

Fix: after 2.8.4
Fix from $1,950 2017-06-13
Fedora HIGH 7.5
CVE-2016-5391

libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).

Fix: after 3.17
Fix from $1,950 2017-06-13
Fedora MEDIUM 5.5
CVE-2016-3696

The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.

Fix: after 2.8.4
Fix from $1,600 2017-06-13
Fedora MEDIUM 5.5
CVE-2016-3095

server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.

Fix: after 2.8.1
Fix from $1,600 2017-06-08
Fedora CRITICAL 9.8
CVE-2016-9961

game-music-emu before 0.6.1 mishandles unspecified integer values.

Fix: after 0.6.0
Fix from $2,300 2017-06-06
Fedora MEDIUM 5.5
CVE-2016-9960

game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).

Fix: after 0.6.0
Fix from $1,600 2017-06-06
Fedora CRITICAL 9.8
CVE-2016-2173EPSS 6%

org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.

Fix: 1.5.5+
Fix from $2,300 2017-04-21
Fedora HIGH 8.8
CVE-2016-0720

Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.

Fix: after 0.9.148
Fix from $1,950 2017-04-21
Fedora HIGH 8.1
CVE-2016-0721

Session fixation vulnerability in pcsd in pcs before 0.9.157.

Fix: after 0.9.156
Fix from $1,950 2017-04-21
Fedora HIGH 7.8
CVE-2016-6299

The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.

Patch available
Fix from $1,950 2017-04-14
Fedora MEDIUM 5.3
CVE-2015-1838

modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

Fix: after 2014.7.3
Fix from $1,600 2017-04-13
Fedora MEDIUM 5.3
CVE-2015-1839

modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

Fix: after 2014.7.3
Fix from $1,600 2017-04-13
Fedora HIGH 7.8
CVE-2014-9114

Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

Fix: after 2.24.2-1
Fix from $1,950 2017-03-31
Fedora MEDIUM 5.5
CVE-2016-8884

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference)…

Patch available
Fix from $1,600 2017-03-28
Fedora HIGH 7.8
CVE-2017-5330

ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.

Fix: after 16.12
Fix from $1,950 2017-03-27
Fedora HIGH 7.5
CVE-2016-10132

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to reg…

Patch available
Fix from $1,950 2017-03-24
Fedora HIGH 7.5
CVE-2016-9398EPSS 6%

The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspe…

Fix: 1.900.17+
Fix from $1,950 2017-03-23
Fedora HIGH 7.5
CVE-2016-9399

The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified v…

Patch available
Fix from $1,950 2017-03-23