Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.5
CVE-2015-7555

Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and …

Fix: after 5.1.1
Fix from $1,600 2016-04-13
Fedora CRITICAL 9.8
CVE-2016-0729EPSS 9%

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C be…

No fix yet
Fix from $2,300 2016-04-07
Fedora HIGH 7.5
CVE-2016-3125EPSS 7%

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weak…

Fix: after 1.3.5
Fix from $1,950 2016-04-05
Fedora HIGH 7.3
CVE-2015-8836

Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (applica…

Fix: after 20070708
Fix from $1,950 2016-03-30
Fedora HIGH 8.6
CVE-2016-1286EPSS 62%

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon …

Fix: 9.9.8 / 9.10.3+
Fix from $1,950 2016-03-09
Fedora MEDIUM 6.8
CVE-2016-1285EPSS 59%

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which all…

Fix: 9.9.8 / 9.10.3+
Fix from $1,600 2016-03-09
Fedora MEDIUM 5.9
CVE-2016-2316

chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and…

Patch available
Fix from $1,600 2016-02-22
Fedora MEDIUM 6.1
CVE-2016-0725

Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2…

Mitigation only
Fix from $1,600 2016-02-22
Fedora MEDIUM 5.4
CVE-2016-2045

Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.3
CVE-2016-2044

libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a cr…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.4
CVE-2016-2043

Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.3
CVE-2016-2042

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) librarie…

Patch available
Fix from $1,600 2016-02-20
Fedora HIGH 7.5
CVE-2016-2041

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm f…

Patch available
Fix from $1,950 2016-02-20
Fedora MEDIUM 5.4
CVE-2016-2040

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote …

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.3
CVE-2016-2039

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token v…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.3
CVE-2016-2038

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafte…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 6.5
CVE-2016-1523

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x befo…

Fix: after 38.5.1
Fix from $1,600 2016-02-13
Fedora HIGH 8.8
CVE-2016-1522EPSS 8%

Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive l…

Fix: after 38.5.1
Fix from $1,950 2016-02-13
Fedora MEDIUM 6.1
CVE-2016-1926

Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to injec…

No fix yet
Fix from $1,600 2016-01-26
Fedora CRITICAL 9.8
CVE-2016-1901

Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Co…

Fix: after 0.11.2
Fix from $2,300 2016-01-20
Fedora HIGH 7.4
CVE-2015-8466

Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.

Fix: after 1.8
Fix from $1,950 2016-01-13
Fedora HIGH 7.5
CVE-2016-1232

The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentic…

Fix: after 0.9.8
Fix from $1,950 2016-01-12
Fedora MEDIUM 5.9
CVE-2016-1231

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbi…

Patch available
Fix from $1,600 2016-01-12
Fedora HIGH 7.4
CVE-2015-8400

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attac…

Fix: after 2.18
Fix from $1,950 2016-01-12
Fedora HIGH 8.4
CVE-2015-6566

zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vaca…

Fix: after 7.2.0
Fix from $1,950 2016-01-11
Fedora HIGH 7.4
CVE-2015-8370

Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, o…

Patch available
Fix from $1,950 2015-12-16
Fedora MEDIUM 5.0
CVE-2015-7218

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, …

Fix: after 42.0
Fix from $1,600 2015-12-16
Fedora MEDIUM 6.8
CVE-2015-7216

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote atta…

Fix: after 42.0
Fix from $1,600 2015-12-16
Fedora MEDIUM 5.0
CVE-2015-7215

The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Pol…

Fix: after 42.0
Fix from $1,600 2015-12-16
Fedora MEDIUM 6.8
CVE-2015-7213

Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR …

Fix: after 42.0
Fix from $1,600 2015-12-16