Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 10.0
CVE-2010-4744

Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.

Fix: 5.9.13+
Fix from $1,950 2011-02-18
Fedora MEDIUM 6.8
CVE-2010-4743

Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a…

Fix: 5.9.13+
Fix from $1,600 2011-02-18
Fedora HIGH 7.5
CVE-2010-3441EPSS 6%

Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to th…

Fix: 5.9.12+
Fix from $1,950 2011-02-18
Fedora MEDIUM 6.0
CVE-2011-0495

Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1…

Fix: 1.4.38.1 / 1.4.39.1+
Fix from $1,600 2011-01-20
Fedora HIGH 7.5
CVE-2010-4168

Multiple use-after-free vulnerabilities in OpenTTD 1.0.x before 1.0.5 allow (1) remote attackers to cause a denial of service (invalid write and daem…

Fix: 1.0.5+
Fix from $1,950 2010-11-17
Fedora HIGH 7.5
CVE-2010-3702

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and pos…

Fix: after 1.3.11
Fix from $1,950 2010-11-05
Fedora CRITICAL 9.8
CVE-2010-2941EPSS 6%

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote a…

Fix: after 1.4.4
Fix from $2,300 2010-11-05
Sssd MEDIUM 5.1
CVE-2010-2940

The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are…

Mitigation only
Fix from $1,600 2010-08-30
Fedora HIGH 8.1
CVE-2010-2547EPSS 5%

Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) a…

Fix: after 2.0.16
Fix from $1,950 2010-08-05
Fedora MEDIUM 6.5
CVE-2010-1637

The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a …

Fix: 10.6.8+
Fix from $1,600 2010-06-22
Fedora MEDIUM 6.5
CVE-2010-0629EPSS 5%

Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated us…

Fix: after 1.6.3
Fix from $1,600 2010-04-07
Fedora MEDIUM 5.0
CVE-2010-0751

The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a de…

Fix: 1.24+
Fix from $1,600 2010-04-06
Fedora HIGH 7.5
CVE-2010-0302

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler …

Fix: 1.4.4+
Fix from $1,950 2010-03-05
Fedora HIGH 7.5
CVE-2010-0013EPSS 12%

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read ar…

Fix: after 11.2
Fix from $1,950 2010-01-09
Fedora HIGH 7.5
CVE-2009-3553

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler …

Fix: 10.5.8 / 10.6.2+
Fix from $1,950 2009-11-20
Fedora HIGH 7.1
CVE-2009-3611

common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, …

Patch available
Fix from $1,950 2009-10-26
Fedora MEDIUM 6.0
CVE-2009-2813

Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Wi…

Mitigation only
Fix from $1,600 2009-09-14
Fedora MEDIUM 6.5
CVE-2009-2416

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers t…

Fix: 2.0.172.43 / 4.0.4+
Fix from $1,600 2009-08-11
Fedora MEDIUM 5.0
CVE-2009-2625EPSS 30%

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Up…

Patch available
Fix from $1,600 2009-08-06
Fedora MEDIUM 5.0
CVE-2009-1902EPSS 14%

The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost reques…

Fix: 2.5.9+
Fix from $1,600 2009-06-03
Fedora HIGH 7.5
CVE-2009-1603

src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect pu…

Patch available
Fix from $1,950 2009-05-11
Fedora HIGH 10.0
CVE-2009-0846EPSS 9%

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 a…

Fix: 1.6.4+
Fix from $1,950 2009-04-09
Fedora HIGH 7.8
CVE-2009-0115

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server …

Fix: after 11.0
Fix from $1,950 2009-03-30
Fedora MEDIUM 6.9
CVE-2009-0314

Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the …

Fix: 0.5.3+
Fix from $1,600 2009-01-28
Fedora MEDIUM 5.9
CVE-2008-4989

The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last cer…

Fix: 2.6.1+
Fix from $1,600 2008-11-13
Fedora HIGH 7.5
CVE-2008-4577

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended…

Fix: 1.1.4+
Fix from $1,950 2008-10-15
Fedora MEDIUM 5.0
CVE-2008-3969

Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors…

Fix: 1.2.3+
Fix from $1,600 2008-09-11
Fedora HIGH 7.5
CVE-2008-3424

Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in …

Fix: 7.0.4+
Fix from $1,950 2008-07-31
Fedora MEDIUM 6.1
CVE-2008-2951

Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct p…

Fix: 0.10.5+
Fix from $1,600 2008-07-27
Fedora CRITICAL 9.8
CVE-2008-2374

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields …

Fix: 3.34+
Fix from $2,300 2008-07-07