Vulnerability index

Browse CVEs

159 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Leap HIGH 7.8
CVE-2016-9957

Stack-based buffer overflow in game-music-emu before 0.6.1.

Patch available
Fix from $1,950 2017-04-12
Leap HIGH 7.8
CVE-2016-9958

game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.

Patch available
Fix from $1,950 2017-04-12
Leap HIGH 7.8
CVE-2016-9959

game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.

Patch available
Fix from $1,950 2017-04-12
Leap CRITICAL 9.8
CVE-2017-5334EPSS 33%

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have…

Fix: after 3.3.25
Fix from $2,300 2017-03-24
Leap CRITICAL 9.8
CVE-2017-5336EPSS 7%

Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote att…

Fix: after 3.3.25
Fix from $2,300 2017-03-24
Leap CRITICAL 9.8
CVE-2017-5337EPSS 6%

Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have uns…

Fix: after 3.3.25
Fix from $2,300 2017-03-24
Leap HIGH 7.5
CVE-2017-5335EPSS 8%

The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of …

Fix: after 3.3.25
Fix from $1,950 2017-03-24
Leap HIGH 7.5
CVE-2017-6318

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

Mitigation only
Fix from $1,950 2017-03-20
Leap HIGH 7.5
CVE-2016-10207

The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake ear…

Patch available
Fix from $1,950 2017-02-28
Opensuse MEDIUM 6.5
CVE-2016-5321

The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff im…

Fix: after 4.0.6
Fix from $1,600 2017-01-20
Leap MEDIUM 6.5
CVE-2016-9435

The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the a…

Fix: after 0.5.3
Fix from $1,600 2017-01-20
Leap MEDIUM 6.5
CVE-2016-9436

parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted…

Fix: after 0.5.3
Fix from $1,600 2017-01-20
Leap HIGH 7.5
CVE-2016-7141EPSS 8%

curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authen…

Fix: after 7.50.1
Fix from $1,950 2016-10-03
Leap MEDIUM 6.8
CVE-2016-6172

PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary…

Fix: after 4.0.0
Fix from $1,600 2016-09-26
Libstorage MEDIUM 5.1
CVE-2016-5746

libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow…

Patch available
Fix from $1,600 2016-09-26
Leap HIGH 8.8
CVE-2016-4069

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for r…

Fix: after 1.1.4
Fix from $1,950 2016-08-25
Leap HIGH 8.4
CVE-2016-3100

kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other user…

Fix: after 5.22.0
Fix from $1,950 2016-07-13
Opensuse MEDIUM 5.3
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote a…

Fix: after 4.6.1
Fix from $1,600 2016-07-05
Leap HIGH 7.5
CVE-2016-5739

The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Co…

Patch available
Fix from $1,950 2016-07-03
Leap MEDIUM 6.1
CVE-2016-5705

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbit…

Patch available
Fix from $1,600 2016-07-03
Leap CRITICAL 9.8
CVE-2016-5703

SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers t…

Patch available
Fix from $2,300 2016-07-03
Leap HIGH 7.5
CVE-2016-5301

The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP respon…

Fix: after 1.1
Fix from $1,950 2016-06-30
Leap HIGH 7.5
CVE-2014-9773

modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, …

Fix: after 7.2.6
Fix from $1,950 2016-06-13
Opensuse HIGH 7.5
CVE-2016-3706EPSS 6%

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attack…

Fix: 2.23+
Fix from $1,950 2016-06-10
Opensuse HIGH 7.8
CVE-2015-5228

The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing f…

Mitigation only
Fix from $1,950 2016-06-07
Leap CRITICAL 9.8
CVE-2015-8863EPSS 7%

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded nu…

Fix: after 1.5
Fix from $2,300 2016-05-06
Opensuse MEDIUM 5.5
CVE-2016-3977

Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via …

Fix: after 5.1.2
Fix from $1,600 2016-04-21
Opensuse HIGH 7.5
CVE-2016-3190

The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (o…

Fix: after 1.12.16
Fix from $1,950 2016-04-21
Opensuse MEDIUM 6.2
CVE-2016-3186

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash)…

Mitigation only
Fix from $1,600 2016-04-19
Leap MEDIUM 5.5
CVE-2016-4036

The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows loca…

Mitigation only
Fix from $1,600 2016-04-18