Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bash HIGH 10.0
CVE-2014-7186EPSS 64%

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds arra…

Mitigation only
Fix from $1,950 2014-09-28
Bash HIGH 10.0
CVE-2014-7187EPSS 58%

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,950 2014-09-28
Bash HIGH 10.0
CVE-2014-6277EPSS 64%

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to…

Patch available
Fix from $1,950 2014-09-27
Glibc MEDIUM 6.8
CVE-2014-0475

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceComma…

Fix: after 2.19
Fix from $1,600 2014-07-29
Gnutls MEDIUM 5.0
CVE-2014-3465EPSS 7%

The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2014-06-10
Gnutls MEDIUM 6.8
CVE-2014-3466EPSS 11%

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allo…

Fix: after 3.1.24
Fix from $1,600 2014-06-03
A2ps MEDIUM 6.8
CVE-2014-0466

The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files o…

Mitigation only
Fix from $1,600 2014-04-03
Gnutls MEDIUM 5.8
CVE-2014-1959

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attack…

Fix: after 3.1.20
Fix from $1,600 2014-03-07
Gnutls MEDIUM 5.8
CVE-2009-5138

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which …

Fix: after 2.7.5
Fix from $1,600 2014-03-07
Gnutls MEDIUM 5.8
CVE-2014-0092EPSS 30%

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from …

Fix: after 3.2.11
Fix from $1,600 2014-03-07
Cpio HIGH 7.2
CVE-2010-4226

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within…

Mitigation only
Fix from $1,950 2014-02-06
Libmicrohttpd MEDIUM 6.4
CVE-2013-7038

The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of servi…

Fix: after 0.9.31
Fix from $1,600 2013-12-13
Libmicrohttpd MEDIUM 5.1
CVE-2013-7039

Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a…

Fix: after 0.9.31
Fix from $1,600 2013-12-13
Glibc MEDIUM 5.0
CVE-2013-4458

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows …

Fix: after 2.18
Fix from $1,600 2013-12-12
Gnutls MEDIUM 5.0
CVE-2013-4466

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote serv…

Patch available
Fix from $1,600 2013-11-20
Gnutls MEDIUM 5.0
CVE-2013-4487

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cau…

Patch available
Fix from $1,600 2013-11-20
Glibc HIGH 7.5
CVE-2012-4412EPSS 17%

Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denia…

Fix: after 2.17
Fix from $1,950 2013-10-09
Glibc MEDIUM 6.8
CVE-2013-4237

sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service …

Fix: after 2.18
Fix from $1,600 2013-10-09
Glibc MEDIUM 5.1
CVE-2012-4424

Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to ca…

Fix: after 2.17
Fix from $1,600 2013-10-09
Glibc MEDIUM 5.1
CVE-2013-4788EPSS 11%

The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the r…

Fix: after 2.17
Fix from $1,600 2013-10-04
Gnutls MEDIUM 5.0
CVE-2013-2116

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over…

Mitigation only
Fix from $1,600 2013-07-03
Glibc MEDIUM 6.8
CVE-2012-0864

Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass th…

No fix yet
Fix from $1,600 2013-05-02
Glibc MEDIUM 6.8
CVE-2009-5029EPSS 8%

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possi…

Fix: after 2.14
Fix from $1,600 2013-05-02
Glibc MEDIUM 5.0
CVE-2011-4609

The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a larg…

Fix: after 2.14
Fix from $1,600 2013-05-02
Glibc MEDIUM 5.0
CVE-2013-1914

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.17 and earlier allows …

Fix: after 2.17
Fix from $1,600 2013-04-29
Gdb MEDIUM 6.9
CVE-2011-4355

GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, whic…

Fix: after 7.4.1
Fix from $1,600 2013-03-05
Glibc MEDIUM 5.0
CVE-2013-0242

Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows contex…

Patch available
Fix from $1,600 2013-02-08
Gnash MEDIUM 6.8
CVE-2012-1175

Integer overflow in the GnashImage::size method in libbase/GnashImage.h in GNU Gnash 0.8.10 allows remote attackers to cause a denial of service (cra…

Mitigation only
Fix from $1,600 2012-08-26
Emacs MEDIUM 6.8
CVE-2012-3479

lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option…

Patch available
Fix from $1,600 2012-08-25
Gnash MEDIUM 5.0
CVE-2011-4328

plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows l…

Fix: after 0.8.9
Fix from $1,600 2012-06-16