Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.8
CVE-2016-4609EPSS 5%

libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watch…

Fix: 1.1.29 / 2.2.2+
Fix from $2,300 2016-07-22
Fedora CRITICAL 9.8
CVE-2016-4608EPSS 5%

libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watch…

Fix: 5.2.1 / 12.4.2+
Fix from $2,300 2016-07-22
Fedora CRITICAL 9.8
CVE-2016-4607EPSS 5%

libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watch…

Fix: 1.1.29 / 2.2.2+
Fix from $2,300 2016-07-22
Fedora MEDIUM 5.9
CVE-2016-2775EPSS 63%

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote at…

Patch available
Fix from $1,600 2016-07-19
Fedora HIGH 8.1
CVE-2016-5386EPSS 5%

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI app…

Fix: 1.6.3+
Fix from $1,950 2016-07-19
Fedora MEDIUM 5.5
CVE-2015-8808

The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) …

Fix: after 1.3.17
Fix from $1,600 2016-07-13
Fedora HIGH 7.5
CVE-2016-5244EPSS 6%

The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remot…

Fix: after 4.6.3
Fix from $1,950 2016-06-27
Fedora HIGH 7.5
CVE-2016-4414

The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dere…

Fix: after 0.12.3
Fix from $1,950 2016-06-13
Fedora CRITICAL 9.1
CVE-2015-8869EPSS 5%

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive in…

Fix: after 4.02.3
Fix from $2,300 2016-06-13
Fedora CRITICAL 9.8
CVE-2016-3720

XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have u…

Fix: after 2.7.3
Fix from $2,300 2016-06-10
Fedora HIGH 7.8
CVE-2016-3096

The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary file…

Fix: after 1.9.6
Fix from $1,950 2016-06-03
Fedora HIGH 7.5
CVE-2016-3075EPSS 8%

Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-depend…

Fix: after 2.23
Fix from $1,950 2016-06-01
Fedora HIGH 7.5
CVE-2016-1234EPSS 5%

Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-depende…

Fix: 2.24+
Fix from $1,950 2016-06-01
Fedora HIGH 7.5
CVE-2016-4021

The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU co…

Fix: after 0.29
Fix from $1,950 2016-05-26
Fedora HIGH 7.5
CVE-2015-8853

The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a de…

Fix: after 5.23.9
Fix from $1,950 2016-05-25
Fedora MEDIUM 6.0
CVE-2016-4037

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU…

Fix: after 2.5.1
Fix from $1,600 2016-05-23
Fedora HIGH 7.5
CVE-2016-2850

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct dow…

Mitigation only
Fix from $1,950 2016-05-13
Fedora HIGH 7.5
CVE-2015-7827

Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, …

Fix: after 1.10.13
Fix from $1,950 2016-05-13
Fedora HIGH 7.8
CVE-2015-8868

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denia…

Mitigation only
Fix from $1,950 2016-05-06
Fedora CRITICAL 9.8
CVE-2016-4002EPSS 6%

Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote …

Fix: after 2.6.2
Fix from $2,300 2016-04-26
Fedora CRITICAL 9.8
CVE-2015-8778EPSS 6%

Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application c…

Fix: after 2.22
Fix from $2,300 2016-04-19
Fedora CRITICAL 9.8
CVE-2014-9761EPSS 6%

Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of se…

No fix yet
Fix from $2,300 2016-04-19
Fedora HIGH 8.8
CVE-2016-3960

Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privi…

Patch available
Fix from $1,950 2016-04-19
Fedora HIGH 7.5
CVE-2016-3071

Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

Mitigation only
Fix from $1,950 2016-04-18
Fedora HIGH 7.8
CVE-2015-8106

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2016-04-18
Fedora HIGH 7.5
CVE-2016-2146

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a deni…

Fix: after 0.11.0
Fix from $1,950 2016-04-15
Fedora HIGH 7.5
CVE-2016-2145

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows rem…

Fix: after 0.11.0
Fix from $1,950 2016-04-15
Fedora MEDIUM 5.9
CVE-2016-0787

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in…

Fix: after 1.6.0
Fix from $1,600 2016-04-13
Fedora HIGH 8.8
CVE-2016-3630

The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, …

Fix: after 3.7.2
Fix from $1,950 2016-04-13
Fedora MEDIUM 6.1
CVE-2015-8807

Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Hor…

Patch available
Fix from $1,600 2016-04-13