Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2015-7212

Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before …

Fix: after 42.0
Fix from $1,950 2015-12-16
Fedora HIGH 10.0
CVE-2015-7205

Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote…

Fix: after 42.0
Fix from $1,950 2015-12-16
Fedora MEDIUM 6.8
CVE-2015-7204

Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via cr…

Fix: after 42.0
Fix from $1,600 2015-12-16
Fedora HIGH 10.0
CVE-2015-7201EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to …

Fix: after 42.0
Fix from $1,950 2015-12-16
Fedora HIGH 7.5
CVE-2015-8393

pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a craf…

Fix: 5.5.32 / 5.6.18+
Fix from $1,950 2015-12-02
Fedora CRITICAL 9.8
CVE-2015-8390

PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized …

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Fedora CRITICAL 9.8
CVE-2015-8389

PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite re…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Fedora HIGH 7.3
CVE-2015-8387

PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer…

Fix: 5.5.32 / 5.6.18+
Fix from $1,950 2015-12-02
Fedora CRITICAL 9.8
CVE-2015-8386EPSS 7%

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a den…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Fedora CRITICAL 9.8
CVE-2015-8383EPSS 6%

PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or poss…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Fedora HIGH 7.5
CVE-2015-8380

The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial …

Fix: after 8.37
Fix from $1,950 2015-12-02
Fedora HIGH 7.2
CVE-2015-7496

GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.

Fix: after 3.18.0
Fix from $1,950 2015-11-24
Fedora HIGH 7.5
CVE-2015-8126EPSS 10%

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.…

Patch available
Fix from $1,950 2015-11-13
Fedora MEDIUM 5.0
CVE-2015-7295

hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote…

Fix: after 2.4.1
Fix from $1,600 2015-11-09
389 Directory Server HIGH 7.5
CVE-2015-3230

389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, whi…

Fix: after 1.3.3.10
Fix from $1,950 2015-10-29
Sssd MEDIUM 6.8
CVE-2015-5292

Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before …

Patch available
Fix from $1,600 2015-10-29
Fedora MEDIUM 6.8
CVE-2015-5400EPSS 21%

Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass in…

Fix: after 3.5.2
Fix from $1,600 2015-09-28
Fedora MEDIUM 5.0
CVE-2015-6524EPSS 9%

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard o…

Mitigation only
Fix from $1,600 2015-08-24
Fedora HIGH 7.2
CVE-2015-5166

Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users t…

Fix: after 4.5.0
Fix from $1,950 2015-08-12
Fedora HIGH 9.3
CVE-2015-5165EPSS 13%

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read pro…

Patch available
Fix from $1,950 2015-08-12
Fedora HIGH 7.2
CVE-2015-5154

Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local…

Fix: after 4.5.0
Fix from $1,950 2015-08-12
Fedora HIGH 7.5
CVE-2015-2059

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly…

Fix: after 1.30
Fix from $1,950 2015-08-12
Fedora MEDIUM 5.0
CVE-2015-1840

jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allo…

Fix: after 3.1.2
Fix from $1,600 2015-07-26
Fedora MEDIUM 6.8
CVE-2015-4588EPSS 9%

Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly exe…

No fix yet
Fix from $1,600 2015-07-01
Fedora MEDIUM 6.8
CVE-2015-0848EPSS 9%

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cr…

Mitigation only
Fix from $1,600 2015-07-01
Fedora HIGH 7.5
CVE-2015-4454

SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute ar…

Fix: after 0.8.8c
Fix from $1,950 2015-06-17
Fedora HIGH 7.5
CVE-2015-4342

SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef…

Fix: after 0.8.8c
Fix from $1,950 2015-06-17
Fedora HIGH 7.8
CVE-2015-1868EPSS 82%

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3…

Mitigation only
Fix from $1,950 2015-05-18
Fedora HIGH 10.0
CVE-2015-0278

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

Fix: 0.10.37+
Fix from $1,950 2015-05-18
Fedora MEDIUM 6.8
CVE-2015-1860EPSS 9%

Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a…

Fix: after 4.8.6
Fix from $1,600 2015-05-12