Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libefiboot MEDIUM 5.5
CVE-2026-6862

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is a…

Mitigation only
Fix from $1,600 2026-04-22
Python Apt MEDIUM 5.5
CVE-2025-6966

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process …

Fix: 0.9.3.11 / 1.6.6+
Fix from $1,600 2025-12-05
Ubuntu MEDIUM 6.5
CVE-2015-5479

The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero …

Fix: after 11.4
Fix from $1,600 2016-04-19
Upstart HIGH 7.2
CVE-2015-2285

The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local us…

Fix: after 1.13.2-0ubuntu7
Fix from $1,950 2015-03-12
Apparmor MEDIUM 6.4
CVE-2014-1424

apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified ve…

Fix: after 2.8.94-0ubuntu1.4
Fix from $1,600 2014-11-24
Language Selector HIGH 7.2
CVE-2011-1842

dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2)…

Fix: after 0.6.6
Fix from $1,950 2011-05-03
Language Selector HIGH 7.2
CVE-2011-0729

dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result…

Fix: after 0.6.6
Fix from $1,950 2011-04-29
Edubuntu HIGH 9.3
CVE-2011-0724

The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installat…

Mitigation only
Fix from $1,950 2011-02-19
Ubuntu Linux HIGH 9.3
CVE-2010-0834

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 ne…

Patch available
Fix from $1,950 2010-08-10
Linux MEDIUM 6.8
CVE-2009-1601

The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working director…

Patch available
Fix from $1,600 2009-05-11
Linux MEDIUM 5.0
CVE-2008-6792

system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES…

Mitigation only
Fix from $1,600 2009-05-07
Ubuntu Linux MEDIUM 6.2
CVE-2009-0578

GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to cha…

Mitigation only
Fix from $1,600 2009-03-05
Linux HIGH 9.3
CVE-2008-4306

Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.

No fix yet
Fix from $1,950 2008-11-04
Linux MEDIUM 5.0
CVE-2008-2285

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier fo…

Mitigation only
Fix from $1,600 2008-05-18
Linux Kernel HIGH 7.5
CVE-2006-7229

The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attackers to …

Mitigation only
Fix from $1,950 2007-11-15
Ubuntu Linux MEDIUM 5.0
CVE-2007-4601

A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses …

Patch available
Fix from $1,600 2007-08-30
Ubuntu Linux HIGH 8.5
CVE-2007-1351EPSS 6%

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remot…

Patch available
Fix from $1,950 2007-04-06
Ubuntu Linux MEDIUM 5.5
CVE-2006-5648

Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list a…

Patch available
Fix from $1,600 2006-12-14
Ubuntu Linux MEDIUM 5.5
CVE-2006-5649

Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to …

Patch available
Fix from $1,600 2006-12-14
Ubuntu Linux MEDIUM 5.4
CVE-2006-5466

Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_R…

Patch available
Fix from $1,600 2006-11-06
Ubuntu Linux HIGH 7.2
CVE-2006-3597

passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option af…

Patch available
Fix from $1,950 2006-07-18
Ubuntu Linux HIGH 7.2
CVE-2006-3378

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, w…

Mitigation only
Fix from $1,950 2006-07-06
Ubuntu Linux HIGH 7.2
CVE-2006-1183

The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable …

No fix yet
Fix from $1,950 2006-03-13
Ubuntu Linux HIGH 7.2
CVE-2006-0151

sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python…

Patch available
Fix from $1,950 2006-01-09
Ubuntu Linux MEDIUM 5.0
CVE-2005-0080

The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is …

Mitigation only
Fix from $1,600 2005-05-02
Ubuntu Linux MEDIUM 5.0
CVE-2004-1007

The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers…

Mitigation only
Fix from $1,600 2005-03-01