Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gnutls MEDIUM 5.0
CVE-2012-1569

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly han…

Fix: after 3.0.15
Fix from $1,600 2012-03-26
Gnutls MEDIUM 5.0
CVE-2012-1573

gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows…

Fix: after 2.12.16
Fix from $1,600 2012-03-26
Gnutls HIGH 7.5
CVE-2012-1663EPSS 5%

Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly h…

Fix: after 3.0.13
Fix from $1,950 2012-03-13
Phpbook MEDIUM 5.0
CVE-2011-3771

phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …

Mitigation only
Fix from $1,600 2011-09-24
Groff MEDIUM 6.5
CVE-2009-5078

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote atta…

Fix: after 10.10.4
Fix from $1,600 2011-06-30
Glibc MEDIUM 6.2
CVE-2011-1095

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to …

Fix: after 2.12.2
Fix from $1,600 2011-04-10
Glibc MEDIUM 5.0
CVE-2011-1659

Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial o…

Fix: after 2.13
Fix from $1,600 2011-04-08
Eglibc MEDIUM 5.1
CVE-2011-1071EPSS 14%

The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause…

Fix: after 2.12.1
Fix from $1,600 2011-04-08
Glibc MEDIUM 6.9
CVE-2009-5064

ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a…

Fix: after 2.1.3
Fix from $1,600 2011-03-30
Gnu Patch MEDIUM 5.8
CVE-2010-4651

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary fil…

Fix: after 2.6.1
Fix from $1,600 2011-03-11
Glibc MEDIUM 5.0
CVE-2010-4051EPSS 40%

The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to…

Patch available
Fix from $1,600 2011-01-13
Glibc MEDIUM 5.0
CVE-2010-4052EPSS 51%

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, al…

Patch available
Fix from $1,600 2011-01-13
Glibc HIGH 7.2
CVE-2010-3856EPSS 11%

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment v…

Fix: after 2.11.2
Fix from $1,950 2011-01-07
Glibc MEDIUM 6.9
CVE-2010-3847EPSS 9%

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIG…

Fix: after 2.11.2
Fix from $1,600 2011-01-07
Glibc MEDIUM 5.0
CVE-2010-3192

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow co…

Fix: 2.26+
Fix from $1,600 2010-10-14
Wget MEDIUM 6.8
CVE-2010-2252

GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allo…

Fix: after 1.12
Fix from $1,600 2010-07-06
Glibc HIGH 7.2
CVE-2010-0296

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not p…

Fix: after 2.11.1
Fix from $1,950 2010-06-01
Glibc MEDIUM 5.1
CVE-2010-0830

Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through …

Patch available
Fix from $1,600 2010-06-01
Glibc MEDIUM 5.0
CVE-2009-4880EPSS 11%

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attacke…

Fix: after 2.10.1
Fix from $1,600 2010-06-01
Glibc MEDIUM 5.0
CVE-2009-4881

Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.…

Fix: after 2.9
Fix from $1,600 2010-06-01
Gnutls MEDIUM 5.0
CVE-2006-7239

The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (c…

Fix: after 1.4.1
Fix from $1,600 2010-05-24
Gnutls HIGH 7.5
CVE-2010-0731

The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value w…

Fix: after 1.2.0
Fix from $1,950 2010-03-26
Cpio MEDIUM 6.8
CVE-2010-0624

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.…

Fix: after 2.10
Fix from $1,600 2010-03-15
Gzip MEDIUM 6.8
CVE-2009-2624

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to ca…

Fix: after 1.3.12
Fix from $1,600 2010-01-29
Gzip MEDIUM 6.8
CVE-2010-0001

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote at…

Fix: after 1.3.13
Fix from $1,600 2010-01-29
Glibc HIGH 7.5
CVE-2010-0015

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.bynam…

Mitigation only
Fix from $1,950 2010-01-14
Grub 2 HIGH 7.2
CVE-2009-4128

GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for phys…

Patch available
Fix from $1,950 2009-12-01
Libtool MEDIUM 6.9
CVE-2009-3736

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to …

Patch available
Fix from $1,600 2009-11-29
Wget MEDIUM 6.8
CVE-2009-3490

GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in…

Fix: after 1.11.4
Fix from $1,600 2009-09-30
Gnutls HIGH 7.5
CVE-2009-2730

libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alte…

Fix: after 2.8.1
Fix from $1,950 2009-08-12