Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Enterprise Linux Desktop HIGH 7.2
CVE-2015-5277

The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow loc…

Fix: after 2.19
Fix from $1,950 2015-12-17
Openstack HIGH 7.2
CVE-2015-5225

Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of s…

Fix: after 2.4.0
Fix from $1,950 2015-11-06
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2015-5220

The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers…

Fix: after 6.4.3
Fix from $1,600 2015-10-27
Enterprise Linux MEDIUM 6.9
CVE-2015-3247

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (h…

Mitigation only
Fix from $1,600 2015-09-08
Enterprise Linux Desktop Supplementary MEDIUM 6.8
CVE-2015-1273

Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to caus…

Fix: after 43.0.2357.134
Fix from $1,600 2015-07-23
Enterprise Linux Desktop HIGH 7.5
CVE-2015-3329EPSS 38%

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5…

Fix: after 5.4.39
Fix from $1,950 2015-06-09
Enterprise Linux Desktop HIGH 7.5
CVE-2015-3307EPSS 8%

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to caus…

Fix: after 5.4.39
Fix from $1,950 2015-06-09
Enterprise Virtualization HIGH 7.7
CVE-2015-3456EPSS 15%

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bou…

Fix: after 2.3.0
Fix from $1,950 2015-05-13
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0348EPSS 9%

Buffer overflow in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux …

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop MEDIUM 6.8
CVE-2014-9664

FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,600 2015-02-08
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2014-7941

The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an inco…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Enterprise Linux HIGH 7.5
CVE-2014-8138EPSS 19%

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or p…

No fix yet
Fix from $1,950 2014-12-24
Tcpdump MEDIUM 5.0
CVE-2014-9140EPSS 6%

Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia…

Fix: after 4.6.2
Fix from $1,600 2014-12-05
Tcpdump MEDIUM 6.4
CVE-2014-8769EPSS 6%

tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segme…

No fix yet
Fix from $1,600 2014-11-20
Enterprise Linux MEDIUM 6.8
CVE-2011-4111

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote…

Fix: after 0.15.1
Fix from $1,600 2014-02-26
Jboss Communications Platform MEDIUM 5.0
CVE-2011-4610

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform befor…

Fix: after 5.1.2
Fix from $1,600 2014-02-10
Enterprise Virtualization Hypervisor HIGH 7.4
CVE-2010-0430

libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other produ…

Fix: after 5.4-2.1
Fix from $1,950 2013-12-27
Enterprise Virtualization MEDIUM 5.0
CVE-2013-4282

Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2013-11-02
Libvirt MEDIUM 5.0
CVE-2013-5651

The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bound…

Fix: after 1.1.1
Fix from $1,600 2013-09-30
Enterprise Linux Desktop HIGH 10.0
CVE-2013-2728EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3324EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3325EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3326EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3327EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3328EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3329EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3330EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3331EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3332EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3333EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16