Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 6.2
CVE-2010-0746

Directory traversal vulnerability in DeviceKit-disks in DeviceKit, as used in Fedora 11 and 12 and possibly other operating systems, allows local use…

Patch available
Fix from $1,600 2014-01-13
Fedora MEDIUM 5.1
CVE-2013-4550

Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr b…

Fix: after 0.8.8
Fix from $1,600 2013-12-24
Fedora MEDIUM 5.9
CVE-2013-6673

Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of tr…

Fix: 2.23 / 24.2+
Fix from $1,600 2013-12-11
Fedora MEDIUM 5.8
CVE-2013-5611

Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a W…

Fix: after 25.0.1
Fix from $1,600 2013-12-11
Fedora MEDIUM 5.0
CVE-2013-2032

MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and S…

Fix: after 1.19.5
Fix from $1,600 2013-11-18
Fedora MEDIUM 6.5
CVE-2013-4222

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is …

Fix: after 2013.1.3
Fix from $1,600 2013-09-30
389 Directory Server MEDIUM 5.0
CVE-2013-4283

ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name …

Fix: after 1.3.0.7
Fix from $1,600 2013-09-10
Fedora MEDIUM 5.0
CVE-2002-2443EPSS 6%

schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses,…

Patch available
Fix from $1,600 2013-05-29
Fedora HIGH 7.5
CVE-2013-1915

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU a…

Fix: 2.7.3+
Fix from $1,950 2013-04-25
Fedora MEDIUM 5.0
CVE-2013-1830

user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles set…

Patch available
Fix from $1,600 2013-03-25
389 Directory Server MEDIUM 5.0
CVE-2013-0312

389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.

Fix: after 1.3.0.3
Fix from $1,600 2013-03-13
Sssd MEDIUM 5.0
CVE-2013-0220

The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_r…

Fix: after 1.9.3
Fix from $1,600 2013-02-24
Fedora CRITICAL 9.1
CVE-2012-3363EPSS 50%

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote atta…

Fix: 1.11.12+
Fix from $2,300 2013-02-13
Fedora HIGH 9.3
CVE-2012-6075

Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flag…

Patch available
Fix from $1,950 2013-02-13
Fedora MEDIUM 5.5
CVE-2012-5656

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML exter…

Fix: 0.48.4+
Fix from $1,600 2013-01-18
Fedora MEDIUM 5.0
CVE-2012-4528EPSS 13%

The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP ap…

Fix: 2.7.0+
Fix from $1,600 2012-12-28
Fedora CRITICAL 9.8
CVE-2012-4406EPSS 7%

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memca…

Fix: 1.7.0+
Fix from $2,300 2012-10-22
Fedora HIGH 7.5
CVE-2012-4415EPSS 14%

Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of…

Fix: after 0.6.2
Fix from $1,950 2012-10-01
389 Directory Server MEDIUM 6.0
CVE-2012-4450

389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users …

Patch available
Fix from $1,600 2012-10-01
Fedora MEDIUM 6.0
CVE-2012-1988

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote aut…

Fix: 2.5.1 / 2.6.15+
Fix from $1,600 2012-05-29
Fedora MEDIUM 6.5
CVE-2011-4107EPSS 13%

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 …

Fix: 3.3.10.5 / 3.4.7.1+
Fix from $1,600 2011-11-17
Fedora HIGH 8.8
CVE-2011-2690

Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that call…

Fix: 1.0.55 / 1.2.45+
Fix from $1,950 2011-07-17
Fedora HIGH 8.8
CVE-2011-2692

The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not pr…

Fix: 1.0.55 / 1.2.45+
Fix from $1,950 2011-07-17
Fedora MEDIUM 6.5
CVE-2011-2501

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows re…

Fix: 1.0.55 / 1.2.45+
Fix from $1,600 2011-07-17
Fedora MEDIUM 6.5
CVE-2011-2691

The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function ca…

Fix: 1.0.55 / 1.2.45+
Fix from $1,600 2011-07-17
Fedora HIGH 7.5
CVE-2011-1755

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory…

Fix: 2.2.14 / 10.6.8+
Fix from $1,950 2011-06-21
Fedora MEDIUM 5.0
CVE-2011-1027

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of serv…

Fix: after 0.8.3.4
Fix from $1,600 2011-03-20
389 Directory Server MEDIUM 5.0
CVE-2011-1067

slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which al…

Fix: after 1.2.8
Fix from $1,600 2011-02-23
389 Directory Server MEDIUM 5.0
CVE-2010-4746

Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (…

Fix: after 1.2.7
Fix from $1,600 2011-02-23
Fedora MEDIUM 5.0
CVE-2011-1002EPSS 29%

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1)…

Fix: after 0.6.28
Fix from $1,600 2011-02-22