Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.8
CVE-2016-7545

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

Patch available
Fix from $1,950 2017-01-19
Fedora HIGH 8.4
CVE-2016-7543

Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

Fix: after 4.3
Fix from $1,950 2017-01-19
Fedora CRITICAL 9.8
CVE-2016-2090

Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigge…

Fix: 0.8.2+
Fix from $2,300 2017-01-13
Fedora MEDIUM 5.9
CVE-2016-10027

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers…

Fix: 4.1.9+
Fix from $1,600 2017-01-12
Fedora CRITICAL 9.8
CVE-2016-8606

The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.

Patch available
Fix from $2,300 2017-01-12
Fedora MEDIUM 5.3
CVE-2016-8605

The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threa…

Fix: after 2.0.12
Fix from $1,600 2017-01-12
Fedora MEDIUM 6.8
CVE-2016-2312

Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a s…

Fix: after 5.5.4
Fix from $1,600 2016-12-23
Fedora HIGH 7.8
CVE-2016-2334EPSS 15%

Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute …

Fix: after 15.14
Fix from $1,950 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7953

Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.

Fix: after 1.0.9
Fix from $2,300 2016-12-13
Fedora HIGH 7.5
CVE-2016-7952

X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecor…

Fix: after 1.2.2
Fix from $1,950 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7951

Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the l…

Fix: after 1.2.2
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7950

The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors invo…

Fix: after 0.9.9
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7949

Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to t…

Fix: after 0.9.9
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7948

X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.

Fix: after 1.5.0
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7947

Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.

Fix: after 1.5.0
Fix from $2,300 2016-12-13
Fedora HIGH 7.5
CVE-2016-7946

X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.

Fix: after 1.7.6
Fix from $1,950 2016-12-13
Fedora HIGH 7.5
CVE-2016-7945

Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite l…

Fix: after 1.7.6
Fix from $1,950 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7944

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, w…

Fix: after 5.0.2
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7943

The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigg…

Fix: after 1.6.3
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7942

The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, wh…

Fix: after 1.6.3
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-5407

The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access…

Fix: after 1.0.10
Fix from $2,300 2016-12-13
Fedora HIGH 8.1
CVE-2016-9014EPSS 6%

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS …

Mitigation only
Fix from $1,950 2016-12-09
Fedora CRITICAL 9.8
CVE-2016-7167EPSS 12%

Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.…

Fix: after 7.50.2
Fix from $2,300 2016-10-07
Fedora HIGH 7.5
CVE-2016-6323

The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI …

Fix: after 2.24
Fix from $1,950 2016-10-07
Fedora HIGH 7.5
CVE-2015-2080EPSS 75%

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via i…

No fix yet
Fix from $1,950 2016-10-07
Fedora CRITICAL 9.8
CVE-2016-7405

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks…

Patch available
Fix from $2,300 2016-10-03
Fedora HIGH 7.5
CVE-2016-6855EPSS 19%

Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attack…

Patch available
Fix from $1,950 2016-09-07
Fedora HIGH 7.8
CVE-2016-5384

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free att…

Fix: 2.12.1+
Fix from $1,950 2016-08-13
Fedora HIGH 7.5
CVE-2016-6515EPSS 59%

The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows r…

Fix: after 7.2
Fix from $1,950 2016-08-07
Fedora CRITICAL 9.8
CVE-2016-4610EPSS 5%

libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watch…

Fix: 1.1.29 / 5.2.1+
Fix from $2,300 2016-07-22