Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.8
CVE-2015-1038

p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.

No fix yet
Fix from $1,600 2015-01-21
Fedora MEDIUM 5.0
CVE-2014-8738EPSS 5%

The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (i…

Fix: after 2.24
Fix from $1,600 2015-01-15
Fedora MEDIUM 5.0
CVE-2014-9527EPSS 8%

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

Fix: after 3.11
Fix from $1,600 2015-01-06
Fedora MEDIUM 5.0
CVE-2014-9449

Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash…

Mitigation only
Fix from $1,600 2015-01-02
Fedora MEDIUM 5.0
CVE-2014-8124

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached sess…

Fix: 2014.1.3 / 2014.2.1+
Fix from $1,600 2014-12-12
Fedora HIGH 7.5
CVE-2014-9274EPSS 6%

UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the strin…

Fix: after 0.21.6
Fix from $1,950 2014-12-09
Fedora HIGH 7.5
CVE-2014-8503EPSS 6%

Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of ser…

Fix: after 2.24
Fix from $1,950 2014-12-09
Fedora HIGH 7.5
CVE-2014-8502

Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denia…

Fix: after 2.24
Fix from $1,950 2014-12-09
Fedora HIGH 7.5
CVE-2014-8485EPSS 7%

The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and pos…

Fix: after 2.24
Fix from $1,950 2014-12-09
Fedora MEDIUM 5.0
CVE-2014-8484EPSS 5%

The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read)…

Fix: after 2.24
Fix from $1,600 2014-12-09
Fedora HIGH 7.5
CVE-2014-9220

SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the ti…

Fix: after 4.0.5
Fix from $1,950 2014-12-03
Fedora HIGH 7.5
CVE-2014-9093

LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code…

Fix: after 4.3.4
Fix from $1,950 2014-11-26
Fedora MEDIUM 5.0
CVE-2014-1572

The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before …

Patch available
Fix from $1,600 2014-10-13
Fedora HIGH 7.5
CVE-2014-6394

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remot…

Fix: after 0.8.3
Fix from $1,950 2014-10-08
Fedora MEDIUM 6.1
CVE-2014-7154

Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, whi…

Patch available
Fix from $1,600 2014-10-02
Fedora MEDIUM 6.5
CVE-2014-6055EPSS 8%

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users …

Fix: after 0.9.9
Fix from $1,600 2014-09-30
Fedora HIGH 10.0
CVE-2014-0247

LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromod…

Mitigation only
Fix from $1,950 2014-07-03
Fedora MEDIUM 5.0
CVE-2014-0477

The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows remote attackers to cause a de…

Fix: after 1.904
Fix from $1,600 2014-07-03
Fedora MEDIUM 6.8
CVE-2014-4668

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthe…

Fix: after 1.2.103
Fix from $1,600 2014-07-02
Fedora MEDIUM 5.0
CVE-2013-2014

OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long req…

Fix: 2013.1+
Fix from $1,600 2014-06-02
Fedora HIGH 7.5
CVE-2014-3152

Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrom…

Fix: after 35.0.1916.113
Fix from $1,950 2014-05-21
Fedora MEDIUM 5.5
CVE-2014-1685

The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of …

Fix: after 1.8.19
Fix from $1,600 2014-05-08
Fedora HIGH 9.3
CVE-2014-1522EPSS 5%

The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 al…

Fix: 2.26 / 29.0+
Fix from $1,950 2014-04-30
Fedora MEDIUM 5.0
CVE-2014-1527

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent t…

Fix: after 28.0
Fix from $1,600 2014-04-30
Fedora MEDIUM 6.5
CVE-2014-2328

lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in…

Fix: after 0.8.8b
Fix from $1,600 2014-04-23
Fedora MEDIUM 5.0
CVE-2013-6370

Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.

Fix: 0.12-20140410+
Fix from $1,600 2014-04-22
Fedora MEDIUM 5.0
CVE-2013-6371

The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data,…

Fix: 0.12-20140410+
Fix from $1,600 2014-04-22
Fedora HIGH 7.5
CVE-2014-2286EPSS 16%

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15…

Patch available
Fix from $1,950 2014-04-18
Fedora MEDIUM 6.9
CVE-2012-2095

The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privi…

Fix: after 1.7.1
Fix from $1,600 2014-04-07
389 Directory Server MEDIUM 6.5
CVE-2014-0132

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and …

Fix: after 1.2.11.25
Fix from $1,600 2014-03-18