Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2015-6816 ganglia-web before 3.7.1 allows remote attackers to bypass authentication. Fedora after 3.7.0 Fix from $2,3002017-08-09 MEDIUM 6.5 CVE-2017-11368 In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requ… Fedora Patch available Fix from $1,6002017-08-09 MEDIUM 5.5 CVE-2015-5203 Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via … Fedora Mitigation only Fix from $1,6002017-08-02 MEDIUM 5.5 CVE-2015-5221 Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote… Fedora after 1.900.1 Fix from $1,6002017-07-25 HIGH 7.5 CVE-2015-5194EPSS 6% The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via … Fedora Patch available Fix from $1,9502017-07-21 HIGH 7.5 CVE-2015-5195EPSS 7% ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or … Fedora after 4.2.7 Fix from $1,9502017-07-21 HIGH 7.5 CVE-2015-5219EPSS 6% The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows re… Fedora Patch available Fix from $1,9502017-07-21 HIGH 7.5 CVE-2015-5300EPSS 9% The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by de… Fedora Patch available Fix from $1,9502017-07-21 HIGH 7.5 CVE-2017-1000050 JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one c… Fedora Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-1000001 FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on. Fedmsg after 0.18.1 Fix from $1,9502017-07-17 HIGH 7.5 CVE-2016-6342 elog 3.1.1 allows remote attackers to post data as any username in the logbook. Fedora Mitigation only Fix from $1,9502017-06-27 HIGH 7.0 CVE-2017-7496 fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount ope… Arm Installer after 1.99.16 Fix from $1,9502017-06-26 HIGH 7.5 CVE-2016-3704 Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords. Fedora after 2.8.4 Fix from $1,9502017-06-13 HIGH 7.5 CVE-2016-5391 libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart). Fedora after 3.17 Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2016-3696 The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key. Fedora after 2.8.4 Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2016-3095 server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key. Fedora after 2.8.1 Fix from $1,6002017-06-08 CRITICAL 9.8 CVE-2016-9961 game-music-emu before 0.6.1 mishandles unspecified integer values. Fedora after 0.6.0 Fix from $2,3002017-06-06 MEDIUM 5.5 CVE-2016-9960 game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). Fedora after 0.6.0 Fix from $1,6002017-06-06 CRITICAL 9.8 CVE-2016-2173EPSS 6% org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. Fedora 1.5.5+ Fix from $2,3002017-04-21 HIGH 8.8 CVE-2016-0720 Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. Fedora after 0.9.148 Fix from $1,9502017-04-21 HIGH 8.1 CVE-2016-0721 Session fixation vulnerability in pcsd in pcs before 0.9.157. Fedora after 0.9.156 Fix from $1,9502017-04-21 HIGH 7.8 CVE-2016-6299 The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file. Fedora Patch available Fix from $1,9502017-04-14 MEDIUM 5.3 CVE-2015-1838 modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. Fedora after 2014.7.3 Fix from $1,6002017-04-13 MEDIUM 5.3 CVE-2015-1839 modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. Fedora after 2014.7.3 Fix from $1,6002017-04-13 HIGH 7.8 CVE-2014-9114 Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code. Fedora after 2.24.2-1 Fix from $1,9502017-03-31 MEDIUM 5.5 CVE-2016-8884 The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference)… Fedora Patch available Fix from $1,6002017-03-28 HIGH 7.8 CVE-2017-5330 ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications. Fedora after 16.12 Fix from $1,9502017-03-27 HIGH 7.5 CVE-2016-10132 regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to reg… Fedora Patch available Fix from $1,9502017-03-24 HIGH 7.5 CVE-2016-9398EPSS 6% The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspe… Fedora 1.900.17+ Fix from $1,9502017-03-23 HIGH 7.5 CVE-2016-9399 The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified v… Fedora Patch available Fix from $1,9502017-03-23