Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 6.8
CVE-2015-1859EPSS 7%

Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attac…

Fix: after 4.8.6
Fix from $1,600 2015-05-12
Fedora MEDIUM 6.8
CVE-2015-1858EPSS 7%

Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a…

Fix: after 4.8.6
Fix from $1,600 2015-05-12
Fedora MEDIUM 5.0
CVE-2015-3148EPSS 14%

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other …

Fix: after 7.5.3.1
Fix from $1,600 2015-04-24
Fedora HIGH 7.5
CVE-2015-3145EPSS 37%

The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to ca…

Fix: after 7.5.3.1
Fix from $1,950 2015-04-24
Fedora MEDIUM 5.0
CVE-2015-0844

The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1)…

Mitigation only
Fix from $1,600 2015-04-14
Fedora MEDIUM 5.8
CVE-2015-0557

Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversa…

Fix: after 3.10.22
Fix from $1,600 2015-04-08
Fedora MEDIUM 5.8
CVE-2015-0556

Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.

Fix: after 3.10.22
Fix from $1,600 2015-04-08
Fedora HIGH 7.1
CVE-2015-2751

Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service …

Patch available
Fix from $1,950 2015-04-01
Fedora MEDIUM 5.0
CVE-2015-1827

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, whic…

Fix: after 4.1.3
Fix from $1,600 2015-03-30
Fedora HIGH 10.0
CVE-2015-1815EPSS 16%

The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via …

Fix: after 3.2.21
Fix from $1,950 2015-03-30
Fedora MEDIUM 5.0
CVE-2015-1609

MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.

Fix: after 2.4.12
Fix from $1,600 2015-03-30
Fedora MEDIUM 5.0
CVE-2015-0295EPSS 6%

The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers t…

Fix: after 5.4.1
Fix from $1,600 2015-03-25
Fedora HIGH 7.5
CVE-2015-0778

osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.

Fix: after 0.150
Fix from $1,950 2015-03-16
Fedora HIGH 7.2
CVE-2015-2151

The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local gu…

Patch available
Fix from $1,950 2015-03-12
Fedora MEDIUM 5.0
CVE-2014-8105

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows r…

Fix: after 1.3.2.26
Fix from $1,600 2015-03-10
Fedora MEDIUM 5.0
CVE-2015-2206

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values …

Patch available
Fix from $1,600 2015-03-09
Fedora MEDIUM 6.4
CVE-2015-1464

RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.

Fix: after 4.0.22
Fix from $1,600 2015-03-09
Fedora MEDIUM 5.0
CVE-2015-0886

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine…

Fix: 0.4+
Fix from $1,600 2015-02-28
Fedora MEDIUM 5.0
CVE-2014-9465

senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.…

Fix: after 2.0
Fix from $1,600 2015-02-19
Fedora HIGH 7.5
CVE-2014-9668

The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, whi…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Fedora HIGH 7.5
CVE-2014-9665

The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG data, which allows remote at…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Fedora HIGH 7.5
CVE-2014-9659EPSS 8%

cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Fedora HIGH 7.5
CVE-2014-9656

The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remot…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Fedora HIGH 7.5
CVE-2015-1462

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."

Fix: after 0.98.5
Fix from $1,950 2015-02-03
Fedora MEDIUM 5.0
CVE-2015-1463

ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler…

Fix: after 0.98.5
Fix from $1,600 2015-02-03
Fedora HIGH 7.5
CVE-2015-1461

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap o…

Fix: after 0.98.5
Fix from $1,950 2015-02-03
Fedora HIGH 7.5
CVE-2014-9328

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."

Fix: after 0.98.5
Fix from $1,950 2015-02-03
Fedora MEDIUM 6.5
CVE-2014-8630

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execu…

Fix: after 4.0.16
Fix from $1,600 2015-02-01
Fedora MEDIUM 5.0
CVE-2014-9639

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a W…

No fix yet
Fix from $1,600 2015-01-23
Fedora MEDIUM 5.0
CVE-2014-9638

oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of …

No fix yet
Fix from $1,600 2015-01-23