Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5127EPSS 8%

A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vul…

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Enterprise Linux Aus CRITICAL 9.8
CVE-2017-7824

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect va…

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2017-5467

A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability a…

Fix: 52.1 / 52.1.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5459

A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, F…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5429

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory co…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5430

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pr…

Fix: 52.1.0 / 53.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5400

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5375EPSS 34%

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thu…

Fix: 45.7.0 / 51.0.1+
Fix from $2,300 2018-06-11
Enterprise Linux Server HIGH 7.5
CVE-2016-9897

Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES.…

Fix: 45.6 / 45.6.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-1089

389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading …

Fix: 1.3.6.15 / 1.4.0.9+
Fix from $1,950 2018-05-09
Enterprise Linux HIGH 7.5
CVE-2018-10184EPSS 8%

An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked…

Fix: 1.8.8+
Fix from $1,950 2018-05-09
Enterprise Linux HIGH 7.5
CVE-2017-15134

A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain L…

Fix: 1.3.6.13 / 1.3.7.9+
Fix from $1,950 2018-03-01
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11281EPSS 34%

Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary …

Fix: after 26.0.0.151
Fix from $2,300 2017-12-01
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11282EPSS 35%

Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code ex…

Fix: after 26.0.0.151
Fix from $2,300 2017-12-01
Enterprise Linux HIGH 7.8
CVE-2017-1000253 KEVEPSS 11%

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ…

Fix: 3.2.70 / 3.4.109+
Fix from $1,950 2017-10-05
Enterprise Linux HIGH 7.8
CVE-2017-1000366

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially …

Patch available
Fix from $1,950 2017-06-19
Enterprise Virtualization Server HIGH 7.0
CVE-2017-1000376

libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that lib…

Fix: 3.2+
Fix from $1,950 2017-06-19
Ovirt Engine MEDIUM 6.5
CVE-2016-3077

The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for a…

Mitigation only
Fix from $1,600 2017-06-06
Mod Cluster HIGH 7.5
CVE-2016-4459

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

Mitigation only
Fix from $1,950 2017-04-12
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9636EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9634EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9635EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop HIGH 7.8
CVE-2016-4302

Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to exe…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Openshift CRITICAL 9.8
CVE-2016-2074EPSS 6%

Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute …

Patch available
Fix from $2,300 2016-07-03
Enterprise Linux Desktop HIGH 7.8
CVE-2015-5260

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash…

Mitigation only
Fix from $1,950 2016-06-07
Satellite MEDIUM 5.6
CVE-2016-0264

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25)…

Mitigation only
Fix from $1,600 2016-05-24
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-2108EPSS 78%

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of serv…

Fix: after 1.0.1n
Fix from $2,300 2016-05-05
Enterprise Linux Desktop CRITICAL 9.8
CVE-2010-5325EPSS 5%

Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of se…

Fix: after 4.0.5
Fix from $2,300 2016-04-15
Openstack HIGH 8.1
CVE-2016-1714EPSS 6%

The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulati…

Fix: after 2.3.0
Fix from $1,950 2016-04-07
Openstack MEDIUM 5.4
CVE-2015-5295

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticat…

Fix: 5.0.1 / 2015.1.3+
Fix from $1,600 2016-01-20