Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
HIGH 8.8 CVE-2018-5127EPSS 8% A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vul… Enterprise Linux Desktop 52.7.0 / 59.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2017-7824 A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect va… Enterprise Linux Aus 52.4.0 / 56.0+ Fix from $2,3002018-06-11 HIGH 7.5 CVE-2017-5467 A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability a… Enterprise Linux Desktop 52.1 / 52.1.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2017-5459 A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, F… Enterprise Linux Desktop 45.9.0 / 52.1.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5429 Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory co… Enterprise Linux Desktop 45.9.0 / 52.1.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5430 Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pr… Enterprise Linux Desktop 52.1.0 / 53.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5400 JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.… Enterprise Linux Desktop 45.8.0 / 52.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5375EPSS 34% JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thu… Enterprise Linux Desktop 45.7.0 / 51.0.1+ Fix from $2,3002018-06-11 HIGH 7.5 CVE-2016-9897 Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES.… Enterprise Linux Server 45.6 / 45.6.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-1089 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading … Enterprise Linux Desktop 1.3.6.15 / 1.4.0.9+ Fix from $1,9502018-05-09 HIGH 7.5 CVE-2018-10184EPSS 8% An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked… Enterprise Linux 1.8.8+ Fix from $1,9502018-05-09 HIGH 7.5 CVE-2017-15134 A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain L… Enterprise Linux 1.3.6.13 / 1.3.7.9+ Fix from $1,9502018-03-01 CRITICAL 9.8 CVE-2017-11281EPSS 34% Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary … Enterprise Linux Desktop after 26.0.0.151 Fix from $2,3002017-12-01 CRITICAL 9.8 CVE-2017-11282EPSS 35% Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code ex… Enterprise Linux Desktop after 26.0.0.151 Fix from $2,3002017-12-01 HIGH 7.8 CVE-2017-1000253 KEVEPSS 11% Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ… Enterprise Linux 3.2.70 / 3.4.109+ Fix from $1,9502017-10-05 HIGH 7.8 CVE-2017-1000366 glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially … Enterprise Linux Patch available Fix from $1,9502017-06-19 HIGH 7.0 CVE-2017-1000376 libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that lib… Enterprise Virtualization Server 3.2+ Fix from $1,9502017-06-19 MEDIUM 6.5 CVE-2016-3077 The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for a… Ovirt Engine Mitigation only Fix from $1,6002017-06-06 HIGH 7.5 CVE-2016-4459 Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9. Mod Cluster Mitigation only Fix from $1,9502017-04-12 CRITICAL 9.8 CVE-2016-9636EPSS 9% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27 CRITICAL 9.8 CVE-2016-9634EPSS 9% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27 CRITICAL 9.8 CVE-2016-9635EPSS 9% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27 HIGH 7.8 CVE-2016-4302 Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to exe… Enterprise Linux Desktop after 3.2.0 Fix from $1,9502016-09-21 CRITICAL 9.8 CVE-2016-2074EPSS 6% Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute … Openshift Patch available Fix from $2,3002016-07-03 HIGH 7.8 CVE-2015-5260 Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash… Enterprise Linux Desktop Mitigation only Fix from $1,9502016-06-07 MEDIUM 5.6 CVE-2016-0264 Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25)… Satellite Mitigation only Fix from $1,6002016-05-24 CRITICAL 9.8 CVE-2016-2108EPSS 78% The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of serv… Enterprise Linux Desktop after 1.0.1n Fix from $2,3002016-05-05 CRITICAL 9.8 CVE-2010-5325EPSS 5% Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of se… Enterprise Linux Desktop after 4.0.5 Fix from $2,3002016-04-15 HIGH 8.1 CVE-2016-1714EPSS 6% The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulati… Openstack after 2.3.0 Fix from $1,9502016-04-07 MEDIUM 5.4 CVE-2015-5295 The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticat… Openstack 5.0.1 / 2015.1.3+ Fix from $1,6002016-01-20