Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop Supplementary MEDIUM 6.8
CVE-2015-1220

Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google …

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2015-1214

Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome be…

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Enterprise Linux Server Aus MEDIUM 5.0
CVE-2013-7423EPSS 6%

The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows re…

Fix: 2.20+
Fix from $1,600 2015-02-24
Enterprise Linux HIGH 10.0
CVE-2015-0240EPSS 88%

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc…

Mitigation only
Fix from $1,950 2015-02-24
Kie Workbench MEDIUM 6.5
CVE-2014-8115

The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac…

Patch available
Fix from $1,600 2015-02-20
Uberfire MEDIUM 6.8
CVE-2014-8114

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte…

Patch available
Fix from $1,600 2015-02-20
Jbpm Designer HIGH 7.5
CVE-2014-3682

XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer …

Patch available
Fix from $1,950 2015-02-20
Ovirt Engine MEDIUM 6.8
CVE-2014-0151

Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for …

Fix: after 3.5.0
Fix from $1,600 2015-02-13
Enterprise Linux Desktop MEDIUM 6.8
CVE-2014-9664

FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,600 2015-02-08
Enterprise Linux Desktop HIGH 7.5
CVE-2014-9657EPSS 5%

The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers…

Patch available
Fix from $1,950 2015-02-08
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-7942

The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2014-7941

The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an inco…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-7926

The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.221…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-7923

The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.221…

Fix: 55.1+
Fix from $1,950 2015-01-22
Cloudforms 3.1 Management Engine MEDIUM 6.5
CVE-2014-7814

SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL command…

Mitigation only
Fix from $1,600 2015-01-16
Cloudforms 3.1 Management Engine HIGH 10.0
CVE-2014-3692

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not…

Mitigation only
Fix from $1,950 2015-01-16
Jboss Data Virtualization MEDIUM 5.0
CVE-2014-0171

XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, all…

Fix: after 6.0.0
Fix from $1,600 2015-01-15
Openstack MEDIUM 5.5
CVE-2014-9493

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete…

Fix: 2014.1.4 / 2014.2.2+
Fix from $1,600 2015-01-07
Enterprise Linux Desktop HIGH 7.2
CVE-2014-7300

GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests,…

Patch available
Fix from $1,950 2014-12-25
Enterprise Linux HIGH 7.5
CVE-2014-8138EPSS 19%

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or p…

No fix yet
Fix from $1,950 2014-12-24
Enterprise Linux MEDIUM 6.8
CVE-2014-8137EPSS 15%

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (…

Fix: after 1.900.1
Fix from $1,600 2014-12-24
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-8108EPSS 10%

The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial…

Patch available
Fix from $1,600 2014-12-18
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-3580EPSS 11%

The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial o…

Patch available
Fix from $1,600 2014-12-18
Enterprise Linux Desktop HIGH 7.5
CVE-2014-7840

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via…

Fix: after 2.1.3
Fix from $1,950 2014-12-12
Tcpdump MEDIUM 5.0
CVE-2014-9140EPSS 6%

Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia…

Fix: after 4.6.2
Fix from $1,600 2014-12-05
Packstack MEDIUM 5.0
CVE-2014-3703

OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration …

Mitigation only
Fix from $1,600 2014-12-02
Undertow MEDIUM 5.0
CVE-2014-7816EPSS 25%

Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Window…

Fix: after 1.2.0
Fix from $1,600 2014-12-01
Resteasy MEDIUM 6.4
CVE-2014-7839

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …

Mitigation only
Fix from $1,600 2014-11-25
Tcpdump MEDIUM 6.4
CVE-2014-8769EPSS 6%

tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segme…

No fix yet
Fix from $1,600 2014-11-20
Tcpdump MEDIUM 5.0
CVE-2014-8767EPSS 5%

Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,600 2014-11-20