Vulnerability index

Browse CVEs

159 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2016-9957 Stack-based buffer overflow in game-music-emu before 0.6.1. Leap Patch available Fix from $1,9502017-04-12 HIGH 7.8 CVE-2016-9958 game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. Leap Patch available Fix from $1,9502017-04-12 HIGH 7.8 CVE-2016-9959 game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. Leap Patch available Fix from $1,9502017-04-12 CRITICAL 9.8 CVE-2017-5334EPSS 33% Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have… Leap after 3.3.25 Fix from $2,3002017-03-24 CRITICAL 9.8 CVE-2017-5336EPSS 7% Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote att… Leap after 3.3.25 Fix from $2,3002017-03-24 CRITICAL 9.8 CVE-2017-5337EPSS 6% Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have uns… Leap after 3.3.25 Fix from $2,3002017-03-24 HIGH 7.5 CVE-2017-5335EPSS 8% The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of … Leap after 3.3.25 Fix from $1,9502017-03-24 HIGH 7.5 CVE-2017-6318 saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet. Leap Mitigation only Fix from $1,9502017-03-20 HIGH 7.5 CVE-2016-10207 The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake ear… Leap Patch available Fix from $1,9502017-02-28 MEDIUM 6.5 CVE-2016-5321 The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff im… Opensuse after 4.0.6 Fix from $1,6002017-01-20 MEDIUM 6.5 CVE-2016-9435 The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the a… Leap after 0.5.3 Fix from $1,6002017-01-20 MEDIUM 6.5 CVE-2016-9436 parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted… Leap after 0.5.3 Fix from $1,6002017-01-20 HIGH 7.5 CVE-2016-7141EPSS 8% curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authen… Leap after 7.50.1 Fix from $1,9502016-10-03 MEDIUM 6.8 CVE-2016-6172 PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary… Leap after 4.0.0 Fix from $1,6002016-09-26 MEDIUM 5.1 CVE-2016-5746 libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow… Libstorage Patch available Fix from $1,6002016-09-26 HIGH 8.8 CVE-2016-4069 Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for r… Leap after 1.1.4 Fix from $1,9502016-08-25 HIGH 8.4 CVE-2016-3100 kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other user… Leap after 5.22.0 Fix from $1,9502016-07-13 MEDIUM 5.3 CVE-2016-5097 phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote a… Opensuse after 4.6.1 Fix from $1,6002016-07-05 HIGH 7.5 CVE-2016-5739 The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Co… Leap Patch available Fix from $1,9502016-07-03 MEDIUM 6.1 CVE-2016-5705 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbit… Leap Patch available Fix from $1,6002016-07-03 CRITICAL 9.8 CVE-2016-5703 SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers t… Leap Patch available Fix from $2,3002016-07-03 HIGH 7.5 CVE-2016-5301 The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP respon… Leap after 1.1 Fix from $1,9502016-06-30 HIGH 7.5 CVE-2014-9773 modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, … Leap after 7.2.6 Fix from $1,9502016-06-13 HIGH 7.5 CVE-2016-3706EPSS 6% Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attack… Opensuse 2.23+ Fix from $1,9502016-06-10 HIGH 7.8 CVE-2015-5228 The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing f… Opensuse Mitigation only Fix from $1,9502016-06-07 CRITICAL 9.8 CVE-2015-8863EPSS 7% Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded nu… Leap after 1.5 Fix from $2,3002016-05-06 MEDIUM 5.5 CVE-2016-3977 Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via … Opensuse after 5.1.2 Fix from $1,6002016-04-21 HIGH 7.5 CVE-2016-3190 The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (o… Opensuse after 1.12.16 Fix from $1,9502016-04-21 MEDIUM 6.2 CVE-2016-3186 Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash)… Opensuse Mitigation only Fix from $1,6002016-04-19 MEDIUM 5.5 CVE-2016-4036 The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows loca… Leap Mitigation only Fix from $1,6002016-04-18