Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2017-7758 An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vu… Enterprise Linux Desktop 52.2.0 / 54.0+ Fix from $2,3002018-06-11 HIGH 7.5 CVE-2017-7762 When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing… Enterprise Linux Desktop 54.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5467 A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability a… Enterprise Linux Desktop 52.1 / 52.1.0+ Fix from $1,9502018-06-11 MEDIUM 6.1 CVE-2017-5466 If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the rel… Enterprise Linux 52.1.0 / 53.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-5456 A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for… Enterprise Linux 52.1.0 / 53.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5459 A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, F… Enterprise Linux Desktop 45.9.0 / 52.1.0+ Fix from $2,3002018-06-11 HIGH 7.5 CVE-2017-5449 A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit… Enterprise Linux 52.1.0 / 53.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5454 A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file … Enterprise Linux 52.1.0 / 53.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5455 The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vuln… Enterprise Linux 52.1.0 / 53.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2017-5428 An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental exten… Enterprise Linux 52.0.1+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5429 Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory co… Enterprise Linux Desktop 45.9.0 / 52.1.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5430 Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pr… Enterprise Linux Desktop 52.1.0 / 53.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5434 A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Th… Enterprise Linux Desktop 45.9.0 / 52.1.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5400 JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.… Enterprise Linux Desktop 45.8.0 / 52.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-9901 HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa… Enterprise Linux Aus 45.6.0 / 50.1+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5375EPSS 34% JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thu… Enterprise Linux Desktop 45.7.0 / 51.0.1+ Fix from $2,3002018-06-11 HIGH 8.8 CVE-2016-9905 A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and … Enterprise Linux Desktop 45.6.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9897 Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES.… Enterprise Linux Server 45.6 / 45.6.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9902 The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allow… Enterprise Linux Desktop 45.6.0 / 50.1+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9904 An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This … Enterprise Linux Desktop 45.6.0 / 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-12020EPSS 9% mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof … Enterprise Linux Desktop Patch available Fix from $1,9502018-06-08 HIGH 7.5 CVE-2016-1000338 In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to… Satellite 1.56+ Fix from $1,9502018-06-01 MEDIUM 6.1 CVE-2018-11627 Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. Cloudforms 2.0.2+ Fix from $1,6002018-05-31 HIGH 7.8 CVE-2016-8656 Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502018-05-22 MEDIUM 5.5 CVE-2018-3639EPSS 61% Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory write… Mrg Realtime Patch available Fix from $1,6002018-05-22 MEDIUM 6.1 CVE-2018-1067 In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to t… Undertow 1.4.25 / 2.0.5+ Fix from $1,6002018-05-21 CRITICAL 9.8 CVE-2018-4944EPSS 9% Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary … Enterprise Linux Desktop after 29.0.0.140 Fix from $2,3002018-05-19 CRITICAL 9.8 CVE-2018-11236EPSS 7% stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functi… Virtualization Host after 2.27 Fix from $2,3002018-05-18 HIGH 7.8 CVE-2018-11237 An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the targ… Virtualization Host after 2.27 Fix from $1,9502018-05-18 HIGH 7.5 CVE-2018-5256 CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w… Tectonic 1.7.9-tectonic.4 / 1.8.4-tectonic.3+ Fix from $1,9502018-05-18