Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2016-9397

The jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified …

Patch available
Fix from $1,950 2017-03-23
Fedora MEDIUM 5.5
CVE-2016-8887

The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer…

Fix: after 1.900.9
Fix from $1,600 2017-03-23
Fedora MEDIUM 5.9
CVE-2016-6225

xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it…

Fix: after 2.3.5
Fix from $1,600 2017-03-23
Fedora MEDIUM 5.5
CVE-2015-4645

Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service…

Fix: after 4.3
Fix from $1,600 2017-03-17
Fedora MEDIUM 5.5
CVE-2017-5849

tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service…

No fix yet
Fix from $1,600 2017-03-15
Fedora MEDIUM 6.1
CVE-2016-7103EPSS 23%

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the close…

Fix: 2.12.42 / 19.1+
Fix from $1,600 2017-03-15
Fedora HIGH 7.5
CVE-2017-6311

gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application cras…

Fix: 2.36.8+
Fix from $1,950 2017-03-10
Fedora HIGH 7.1
CVE-2017-6313

Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-b…

Fix: 2.36.12+
Fix from $1,950 2017-03-10
Fedora MEDIUM 5.5
CVE-2017-6312

Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash)…

Fix: 2.36.12+
Fix from $1,600 2017-03-10
Fedora MEDIUM 5.5
CVE-2017-6314

The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a…

Fix: 2.36.12+
Fix from $1,600 2017-03-10
Fedora HIGH 7.5
CVE-2016-7969

The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via u…

Fix: after 0.13.3
Fix from $1,950 2017-03-03
Fedora HIGH 7.5
CVE-2016-7970

Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unsp…

Fix: after 0.13.3
Fix from $1,950 2017-03-03
Fedora HIGH 7.5
CVE-2016-7972EPSS 5%

The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation…

Fix: after 0.13.3
Fix from $1,950 2017-03-03
Fedora CRITICAL 9.8
CVE-2017-5885

Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers …

Fix: after 0.6.0
Fix from $2,300 2017-02-28
Fedora HIGH 7.8
CVE-2017-5884

gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via t…

Fix: after 0.6.0
Fix from $1,950 2017-02-28
Fedora CRITICAL 9.8
CVE-2016-9400

The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical me…

Fix: 0.6.4+
Fix from $2,300 2017-02-22
Fedora HIGH 7.5
CVE-2017-5357

regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.

Fix: after 1.14
Fix from $1,950 2017-02-17
Fedora CRITICAL 9.8
CVE-2016-4861

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection atta…

Fix: after 1.12.19
Fix from $2,300 2017-02-17
Fedora CRITICAL 9.8
CVE-2016-6233

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection atta…

Fix: after 1.12.19
Fix from $2,300 2017-02-17
Fedora HIGH 7.8
CVE-2016-8693

Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (c…

Fix: after 1.900.5
Fix from $1,950 2017-02-15
Fedora HIGH 7.5
CVE-2016-6866

slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference and crash.

Fix: after 1.3
Fix from $1,950 2017-02-15
Fedora MEDIUM 5.5
CVE-2016-8690

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer deref…

Fix: after 1.900.29
Fix from $1,600 2017-02-15
Fedora MEDIUM 5.5
CVE-2016-8692

The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-…

Fix: after 1.900.3
Fix from $1,600 2017-02-15
Fedora CRITICAL 9.8
CVE-2013-7459EPSS 10%

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execut…

Fix: after 2.6.1
Fix from $2,300 2017-02-15
Fedora MEDIUM 5.5
CVE-2016-4796

Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (…

Fix: after 2.1.0
Fix from $1,600 2017-02-03
Fedora MEDIUM 5.5
CVE-2016-4797

Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service…

Fix: after 2.1.0
Fix from $1,600 2017-02-03
Fedora HIGH 7.5
CVE-2016-9108

Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows …

Fix: after 2016-10-31
Fix from $1,950 2017-02-03
Fedora MEDIUM 5.5
CVE-2016-8568

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat…

Fix: after 0.24.2
Fix from $1,600 2017-02-03
Fedora MEDIUM 5.5
CVE-2016-8569

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a …

Fix: after 0.24.2
Fix from $1,600 2017-02-03
Fedora HIGH 7.5
CVE-2015-8854

The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "c…

Fix: 0.3.4+
Fix from $1,950 2017-01-23