Vulnerability index

Browse CVEs

159 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opensuse HIGH 7.8
CVE-2015-7552

Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2016-04-18
Leap CRITICAL 9.8
CVE-2016-4007

Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2…

Patch available
Fix from $2,300 2016-04-13
Leap MEDIUM 6.2
CVE-2015-5969

The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 4…

Mitigation only
Fix from $1,600 2016-04-08
Leap MEDIUM 5.3
CVE-2016-3119EPSS 40%

The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through…

Patch available
Fix from $1,600 2016-03-26
Leap HIGH 8.8
CVE-2016-2329

libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip values and YCbCr chrominance subsampling factors, which allows remot…

Fix: after 2.8.5
Fix from $1,950 2016-02-12
Leap HIGH 7.5
CVE-2015-8078

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i…

Mitigation only
Fix from $1,950 2015-12-03
Leap HIGH 7.5
CVE-2015-8076

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain s…

Mitigation only
Fix from $1,950 2015-12-03
Opensuse HIGH 9.3
CVE-2015-7805EPSS 13%

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF f…

No fix yet
Fix from $1,950 2015-11-17
Leap MEDIUM 5.0
CVE-2015-7940

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obt…

Fix: after 1.50
Fix from $1,600 2015-11-09
Opensuse MEDIUM 6.8
CVE-2015-7673EPSS 5%

io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-b…

Fix: after 2.31.4
Fix from $1,600 2015-10-26
Opensuse HIGH 10.0
CVE-2015-5957

Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.

Fix: after 3.1.14
Fix from $1,950 2015-09-28
Opensuse MEDIUM 5.0
CVE-2015-5185

The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer deref…

No fix yet
Fix from $1,600 2015-09-28
Opensuse HIGH 7.8
CVE-2014-9744

Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello mess…

Fix: after 1.3.8
Fix from $1,950 2015-08-24
Evergreen HIGH 10.0
CVE-2015-5130EPSS 50%

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.19…

Fix: after 18.0.0.209
Fix from $1,950 2015-08-14
Opensuse MEDIUM 5.0
CVE-2015-4144

The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain t…

Mitigation only
Fix from $1,600 2015-06-15
Opensuse HIGH 9.3
CVE-2015-0492

Unspecified vulnerability in Oracle Java SE 7u76 and 8u40, and JavaFX 2.2.76, allows remote attackers to affect confidentiality, integrity, and avail…

Mitigation only
Fix from $1,950 2015-04-16
Opensuse HIGH 10.0
CVE-2014-9488

The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which trig…

Fix: after 471
Fix from $1,950 2015-04-14
Opensuse HIGH 7.5
CVE-2014-9462

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name i…

Fix: after 3.2.3
Fix from $1,950 2015-03-31
Opensuse MEDIUM 5.0
CVE-2014-3619

The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" frag…

Mitigation only
Fix from $1,600 2015-03-27
Opensuse MEDIUM 5.0
CVE-2015-1419EPSS 7%

Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file…

Fix: after 3.0.2
Fix from $1,600 2015-01-28
Opensuse HIGH 7.5
CVE-2015-1182

The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointe…

Mitigation only
Fix from $1,950 2015-01-27
Opensuse HIGH 7.2
CVE-2014-8148

The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system…

Mitigation only
Fix from $1,950 2015-01-26
Opensuse MEDIUM 6.5
CVE-2014-8959

Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7…

Patch available
Fix from $1,600 2014-11-30
Opensuse MEDIUM 6.8
CVE-2014-3429

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary c…

Patch available
Fix from $1,600 2014-08-07
Opensuse HIGH 10.0
CVE-2014-2977EPSS 7%

Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote a…

Mitigation only
Fix from $1,950 2014-06-11
Opensuse MEDIUM 5.0
CVE-2011-4091

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows …

Fix: after 1.3.13
Fix from $1,600 2014-02-10
Opensuse HIGH 7.2
CVE-2013-1090

The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, …

Mitigation only
Fix from $1,950 2013-12-06
Opensuse HIGH 7.8
CVE-2012-0425

LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows contex…

Mitigation only
Fix from $1,950 2013-12-02
Opensuse HIGH 7.2
CVE-2012-0427

yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain pri…

No fix yet
Fix from $1,950 2013-12-02
Opensuse HIGH 7.5
CVE-2013-4115EPSS 43%

Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a d…

Patch available
Fix from $1,950 2013-08-09