Vulnerability index

Browse CVEs

6,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux MEDIUM 6.5
CVE-2016-0777EPSS 63%

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive infor…

Fix: after 15.07
Fix from $1,600 2016-01-14
Linux CRITICAL 9.8
CVE-2015-8668EPSS 14%

Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to ex…

Fix: after 4.0.6
Fix from $2,300 2016-01-08
Linux MEDIUM 5.0
CVE-2015-8000EPSS 55%

db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion fai…

Patch available
Fix from $1,600 2015-12-16
Linux HIGH 7.5
CVE-2015-3276EPSS 5%

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, whic…

Patch available
Fix from $1,950 2015-12-07
HTTP Server MEDIUM 5.3
CVE-2015-3195EPSS 39%

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before …

Fix: 0.9.8zh / 1.0.0t+
Fix from $1,600 2015-12-06
Linux CRITICAL 9.8
CVE-2015-8391EPSS 6%

The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $2,300 2015-12-02
Linux HIGH 7.5
CVE-2015-8388EPSS 7%

PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote at…

Fix: after 8.37
Fix from $1,950 2015-12-02
Linux HIGH 7.5
CVE-2015-8385EPSS 6%

PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to…

Fix: after 8.37
Fix from $1,950 2015-12-02
Linux HIGH 7.5
CVE-2015-2328EPSS 5%

PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denia…

Fix: after 8.35
Fix from $1,950 2015-12-02
Virtual Desktop Infrastructure CRITICAL 9.8
CVE-2015-4852 KEVEPSS 96%

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands…

Fix: after 3.5.2
Fix from $2,300 2015-11-18
Openjdk HIGH 10.0
CVE-2014-8873

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, …

Mitigation only
Fix from $1,950 2015-11-09
Jdk MEDIUM 5.0
CVE-2015-4916

Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different…

No fix yet
Fix from $1,600 2015-10-22
Oracle And Sun Systems Product Suite HIGH 10.0
CVE-2015-4915

Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote …

Mitigation only
Fix from $1,950 2015-10-22
Jrockit MEDIUM 5.0
CVE-2015-4911

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect avail…

Mitigation only
Fix from $1,600 2015-10-22
Fusion Middleware MEDIUM 5.0
CVE-2015-4909

Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.4.0, 12.1.2.0.0, and 12.1.3.0.0 allows remote attacke…

Mitigation only
Fix from $1,600 2015-10-22
Javafx MEDIUM 5.0
CVE-2015-4908

Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different…

No fix yet
Fix from $1,600 2015-10-22
Javafx MEDIUM 5.0
CVE-2015-4906

Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors related to J…

Mitigation only
Fix from $1,600 2015-10-22
Jdk MEDIUM 5.0
CVE-2015-4903

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via v…

Mitigation only
Fix from $1,600 2015-10-22
Jdk HIGH 9.3
CVE-2015-4901

Unspecified vulnerability in Oracle Java SE 8u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors r…

Mitigation only
Fix from $1,950 2015-10-22
Database Server MEDIUM 6.5
CVE-2015-4900

Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated …

Mitigation only
Fix from $1,600 2015-10-21
Jrockit MEDIUM 5.0
CVE-2015-4893EPSS 5%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect avail…

Patch available
Fix from $1,600 2015-10-21
Database Server MEDIUM 6.5
CVE-2015-4888

Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to af…

Patch available
Fix from $1,600 2015-10-21
Peoplesoft Products MEDIUM 6.0
CVE-2015-4887

Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect co…

Patch available
Fix from $1,600 2015-10-21
E Business Suite MEDIUM 6.4
CVE-2015-4886

Unspecified vulnerability in the Oracle Report Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remo…

Patch available
Fix from $1,600 2015-10-21
E Business Suite MEDIUM 5.0
CVE-2015-4884

Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4…

Patch available
Fix from $1,600 2015-10-21
Jdk HIGH 10.0
CVE-2015-4883EPSS 6%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, inte…

Patch available
Fix from $1,950 2015-10-21
Jdk HIGH 10.0
CVE-2015-4881EPSS 6%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, inte…

Patch available
Fix from $1,950 2015-10-21
Jdk MEDIUM 5.0
CVE-2015-4882

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect availability via vect…

Patch available
Fix from $1,600 2015-10-21
Enterprise Manager Grid Control MEDIUM 5.0
CVE-2015-4875

Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows re…

Patch available
Fix from $1,600 2015-10-21
Database Server HIGH 7.2
CVE-2015-4873

Unspecified vulnerability in the Database Scheduler component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect…

Patch available
Fix from $1,950 2015-10-21