Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2015-1220 Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google … Enterprise Linux Desktop Supplementary after 40.0.2214.115 Fix from $1,6002015-03-09 HIGH 7.5 CVE-2015-1214 Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome be… Enterprise Linux Desktop Supplementary after 40.0.2214.115 Fix from $1,9502015-03-09 MEDIUM 5.0 CVE-2013-7423EPSS 6% The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows re… Enterprise Linux Server Aus 2.20+ Fix from $1,6002015-02-24 HIGH 10.0 CVE-2015-0240EPSS 88% The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc… Enterprise Linux Mitigation only Fix from $1,9502015-02-24 MEDIUM 6.5 CVE-2014-8115 The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac… Kie Workbench Patch available Fix from $1,6002015-02-20 MEDIUM 6.8 CVE-2014-8114 The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte… Uberfire Patch available Fix from $1,6002015-02-20 HIGH 7.5 CVE-2014-3682 XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer … Jbpm Designer Patch available Fix from $1,9502015-02-20 MEDIUM 6.8 CVE-2014-0151 Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for … Ovirt Engine after 3.5.0 Fix from $1,6002015-02-13 MEDIUM 6.8 CVE-2014-9664 FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of servi… Enterprise Linux Desktop Patch available Fix from $1,6002015-02-08 HIGH 7.5 CVE-2014-9657EPSS 5% The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers… Enterprise Linux Desktop Patch available Fix from $1,9502015-02-08 HIGH 7.5 CVE-2014-7942 The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause… Enterprise Linux Desktop Supplementary after 40.0.2214.85 Fix from $1,9502015-01-22 MEDIUM 5.0 CVE-2014-7941 The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an inco… Enterprise Linux Desktop Supplementary after 40.0.2214.85 Fix from $1,6002015-01-22 HIGH 7.5 CVE-2014-7926 The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.221… Enterprise Linux Desktop Supplementary after 40.0.2214.85 Fix from $1,9502015-01-22 HIGH 7.5 CVE-2014-7923 The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.221… Enterprise Linux Desktop Supplementary 55.1+ Fix from $1,9502015-01-22 MEDIUM 6.5 CVE-2014-7814 SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL command… Cloudforms 3.1 Management Engine Mitigation only Fix from $1,6002015-01-16 HIGH 10.0 CVE-2014-3692 The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not… Cloudforms 3.1 Management Engine Mitigation only Fix from $1,9502015-01-16 MEDIUM 5.0 CVE-2014-0171 XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, all… Jboss Data Virtualization after 6.0.0 Fix from $1,6002015-01-15 MEDIUM 5.5 CVE-2014-9493 The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete… Openstack 2014.1.4 / 2014.2.2+ Fix from $1,6002015-01-07 HIGH 7.2 CVE-2014-7300 GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests,… Enterprise Linux Desktop Patch available Fix from $1,9502014-12-25 HIGH 7.5 CVE-2014-8138EPSS 19% Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or p… Enterprise Linux No fix yet Fix from $1,9502014-12-24 MEDIUM 6.8 CVE-2014-8137EPSS 15% Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (… Enterprise Linux after 1.900.1 Fix from $1,6002014-12-24 MEDIUM 5.0 CVE-2014-8108EPSS 10% The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial… Enterprise Linux Desktop Patch available Fix from $1,6002014-12-18 MEDIUM 5.0 CVE-2014-3580EPSS 11% The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial o… Enterprise Linux Desktop Patch available Fix from $1,6002014-12-18 HIGH 7.5 CVE-2014-7840 The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via… Enterprise Linux Desktop after 2.1.3 Fix from $1,9502014-12-12 MEDIUM 5.0 CVE-2014-9140EPSS 6% Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia… Tcpdump after 4.6.2 Fix from $1,6002014-12-05 MEDIUM 5.0 CVE-2014-3703 OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration … Packstack Mitigation only Fix from $1,6002014-12-02 MEDIUM 5.0 CVE-2014-7816EPSS 25% Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Window… Undertow after 1.2.0 Fix from $1,6002014-12-01 MEDIUM 6.4 CVE-2014-7839 DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which … Resteasy Mitigation only Fix from $1,6002014-11-25 MEDIUM 6.4 CVE-2014-8769EPSS 6% tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segme… Tcpdump No fix yet Fix from $1,6002014-11-20 MEDIUM 5.0 CVE-2014-8767EPSS 5% Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of servi… Tcpdump No fix yet Fix from $1,6002014-11-20