Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux CRITICAL 9.8
CVE-2015-4602EPSS 11%

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remot…

Fix: after 5.4.39
Fix from $2,300 2016-05-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-4601EPSS 8%

PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected d…

Fix: after 5.6.6
Fix from $2,300 2016-05-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-4600EPSS 11%

The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service …

Fix: after 5.4.39
Fix from $2,300 2016-05-16
Enterprise Linux Desktop MEDIUM 6.5
CVE-2015-4598

PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers…

Fix: after 5.4.41
Fix from $1,600 2016-05-16
Enterprise Linux MEDIUM 6.5
CVE-2015-3411

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers …

Fix: after 5.4.39
Fix from $1,600 2016-05-16
Enterprise Linux Desktop Supplementary CRITICAL 9.8
CVE-2016-1666

Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 50.0.2661.87
Fix from $2,300 2016-05-14
Enterprise Linux Desktop Supplementary MEDIUM 6.5
CVE-2016-1665

The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison oper…

Fix: after 50.0.2661.87
Fix from $1,600 2016-05-14
Enterprise Linux Desktop Supplementary HIGH 8.8
CVE-2016-1663

The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as …

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Enterprise Linux Desktop Supplementary HIGH 8.0
CVE-2016-1661

Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same …

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Enterprise Linux Desktop Supplementary HIGH 8.8
CVE-2016-1660

Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which all…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4117 KEVEPSS 94%

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May …

Fix: after 21.0.0.226
Fix from $2,300 2016-05-11
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3718 KEVEPSS 77%

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (…

Patch available
Fix from $1,600 2016-05-05
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3715 KEVEPSS 75%

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

Patch available
Fix from $1,600 2016-05-05
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-2108EPSS 78%

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of serv…

Fix: after 1.0.1n
Fix from $2,300 2016-05-05
Enterprise Linux Desktop MEDIUM 5.9
CVE-2016-2107EPSS 89%

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which …

Fix: after 1.0.1s
Fix from $1,600 2016-05-05
Enterprise Linux Desktop HIGH 7.5
CVE-2016-2105EPSS 40%

Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to …

Fix: after 5.7.12
Fix from $1,950 2016-05-05
Icedtea7 MEDIUM 5.9
CVE-2016-0695

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confi…

Fix: after 2.6.6
Fix from $1,600 2016-04-21
Enterprise Linux MEDIUM 5.5
CVE-2016-0666

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.…

Fix: 5.5.49 / 10.0.25+
Fix from $1,600 2016-04-21
Enterprise Linux MEDIUM 5.5
CVE-2016-0665

Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to …

Fix: after 5.7.10
Fix from $1,600 2016-04-21
Enterprise Linux MEDIUM 5.5
CVE-2016-0649

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.…

Fix: 5.5.48 / 10.0.24+
Fix from $1,600 2016-04-21
Enterprise Linux CRITICAL 9.8
CVE-2016-0639EPSS 10%

Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and…

Fix: after 5.7.11
Fix from $2,300 2016-04-21
Enterprise Linux HIGH 7.5
CVE-2016-0741

slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of ser…

Patch available
Fix from $1,950 2016-04-19
Openstack HIGH 7.5
CVE-2015-5271

The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift)…

Patch available
Fix from $1,950 2016-04-15
Enterprise Linux Desktop CRITICAL 9.8
CVE-2010-5325EPSS 5%

Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of se…

Fix: after 4.0.5
Fix from $2,300 2016-04-15
Libvirt MEDIUM 6.5
CVE-2015-5247

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of s…

Mitigation only
Fix from $1,600 2016-04-14
Satellite MEDIUM 6.1
CVE-2016-3079

Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary w…

Patch available
Fix from $1,600 2016-04-14
Satellite MEDIUM 6.1
CVE-2016-2103

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the …

Mitigation only
Fix from $1,600 2016-04-14
Enterprise Linux Desktop Supplementary HIGH 8.8
CVE-2015-8540EPSS 6%

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.…

Patch available
Fix from $1,950 2016-04-14
Satellite MEDIUM 5.4
CVE-2015-0284

Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitra…

Patch available
Fix from $1,600 2016-04-14
Enterprise Linux MEDIUM 5.9
CVE-2016-0739

libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange me…

Fix: after 0.7.2
Fix from $1,600 2016-04-13