thunderbird vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the thunderbird package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

*
  • H
Asymmetric Resource Consumption (Amplification)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Inefficient Regular Expression Complexity

*
  • H
Buffer Overflow

*
  • M
Exposure of System Data to an Unauthorized Control Sphere

*
  • H
Use After Free

*
  • H
Incorrect Type Conversion or Cast

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • L
Improperly Implemented Security Check for Standard

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-bounds Write

*
  • M
Cross-site Scripting (XSS)

*
  • M
Missing Required Cryptographic Step

*
  • H
Out-of-bounds Write

*
  • H
Use of Uninitialized Resource

*
  • H
Out-of-bounds Read

*
  • H
CVE-2024-7518

*
  • H
Improper Privilege Management

*
  • H
Use After Free

*
  • M
CVE-2024-7529

*
  • M
Missing Required Cryptographic Step

*
  • H
Use After Free

*
  • H
Use After Free

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Missing Required Cryptographic Step

*
  • M
Out-of-Bounds

*
  • M
Improper Preservation of Permissions

*
  • M
Out-of-Bounds

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Covert Timing Channel

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Improper Access Control

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Use After Free

*
  • M
Buffer Overflow

*
  • H
Improper Check for Unusual or Exceptional Conditions

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
User Interface (UI) Misrepresentation of Critical Information

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • M
Integer Overflow or Wraparound

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • M
Product UI does not Warn User of Unsafe Actions

*
  • H
Out-of-bounds Read

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Use After Free

*
  • L
Resource Exhaustion

*
  • H
Directory Traversal

*
  • H
Register Interface Allows Software Access to Sensitive Data or Security Settings

*
  • H
Buffer Overflow

*
  • H
Integer Overflow or Wraparound

*
  • M
The UI Performs the Wrong Action

*
  • M
Cross-site Scripting (XSS)

*
  • M
Use After Free

*
  • H
CVE-2024-2616

*
  • H
Unchecked Return Value

*
  • M
Information Exposure

*
  • H
Missing Encryption of Sensitive Data

*
  • M
Arbitrary Code Injection

*
  • H
The UI Performs the Wrong Action

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Out-of-bounds Read

*
  • H
Buffer Overflow

*
  • L
Incorrect Conversion between Numeric Types

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
The UI Performs the Wrong Action

*
  • M
Inadequate Encryption Strength

*
  • M
Improper Input Validation

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Improper Input Validation

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Out-of-bounds Write

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Buffer Overflow

*
  • M
Information Exposure

*
  • H
Improper Verification of Cryptographic Signature

*
  • H
Improper Verification of Cryptographic Signature

*
  • M
Use After Free

*
  • M
Heap-based Buffer Overflow

*
  • M
Improper Input Validation

*
  • H
Buffer Overflow

*
  • M
Use After Free

*
  • M
Heap-based Buffer Overflow

*
  • L
Improper Input Validation

*
  • M
Race Condition

*
  • H
Heap-based Buffer Overflow

*
  • H
Use After Free

*
  • H
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • H
Use After Free

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Buffer Overflow

*
  • H
Buffer Overflow

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Product UI does not Warn User of Unsafe Actions

*
  • M
Multiple Interpretations of UI Input

*
  • M
Open Redirect

*
  • M
Memory Leak

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • H
Out-of-bounds Write

*
  • H
Resource Exhaustion

*
  • M
Information Exposure

*
  • H
Use After Free

*
  • M
Compilation with Insufficient Warnings or Errors

*
  • H
Use After Free

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • M
Out-of-Bounds

*
  • H
Buffer Overflow

*
  • L
Incorrect Behavior Order: Early Validation

*
  • M
Authentication Bypass

*
  • M
Authentication Bypass

*
  • L
Reliance on Cookies without Validation and Integrity Checking in a Security Decision

*
  • H
Buffer Overflow

*
  • H
Improper Handling of Insufficient Permissions or Privileges

*
  • H
Race Condition

*
  • H
Out-of-bounds Read

*
  • H
Improper Input Validation

*
  • H
Inclusion of Functionality from Untrusted Control Sphere

*
  • H
Buffer Overflow

*
  • H
Buffer Overflow

*
  • M
Unrestricted Upload of File with Dangerous Type

*
  • M
Authentication Bypass

*
  • H
Use After Free

*
  • M
Compilation with Insufficient Warnings or Errors

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • M
Resource Exhaustion

*
  • H
Buffer Overflow

*
  • H
The UI Performs the Wrong Action

*
  • H
Buffer Overflow

*
  • H
Improper Handling of Insufficient Permissions or Privileges

*
  • H
User Interface (UI) Misrepresentation of Critical Information

*
  • M
Use of Uninitialized Variable

*
  • H
Out-of-bounds Read

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Resource Exhaustion

*
  • H
Double Free

*
  • M
Resource Exhaustion

*
  • H
Product UI does not Warn User of Unsafe Actions

*
  • L
Incorrect Calculation

*
  • H
Direct Request ('Forced Browsing')

*
  • M
Failure to Sanitize Special Element

*
  • M
Unrestricted Upload of File with Dangerous Type

*
  • H
Buffer Overflow

*
  • H
Reachable Assertion

*
  • H
Out-of-Bounds

*
  • M
Out-of-Bounds

*
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Incorrect Type Conversion or Cast

*
  • M
Out-of-bounds Read

*
  • H
Buffer Overflow

*
  • H
Arbitrary Code Injection

*
  • L
The UI Performs the Wrong Action

*
  • H
Use After Free

*
  • L
Improper Handling of Alternate Encoding

*
  • H
Insufficient UI Warning of Dangerous Operations

*
  • H
Buffer Overflow

*
  • M
Cross-site Scripting (XSS)

*
  • H
Use After Free

*
  • H
Incorrect Type Conversion or Cast

*
  • H
Incorrect Synchronization

*
  • M
Out-of-bounds Write

*
  • H
Buffer Overflow

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Improper Check for Certificate Revocation

*
  • H
Buffer Overflow

*
  • M
CVE-2023-23602

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • L
Incorrect Regular Expression

*
  • M
Arbitrary Command Injection

*
  • H
Use of Unmaintained Third Party Components

*
  • H
Multiple Interpretations of UI Input

*
  • L
Insufficient UI Warning of Dangerous Operations

*
  • H
Buffer Overflow

*
  • H
Out-of-Bounds

*
  • H
Out-of-bounds Read

*
  • M
Truncation of Security-relevant Information

*
  • H
Out-of-Bounds

*
  • M
Use After Free

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • H
Information Exposure

*
  • M
Information Exposure

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • H
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Information Exposure

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Information Exposure

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Sensitive Cookie with Improper SameSite Attribute

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Use After Free

*
  • H
Use After Free

*
  • M
Cross-site Scripting (XSS)

*
  • M
Resource Exhaustion

*
  • M
Buffer Overflow

*
  • H
Inclusion of Functionality from Untrusted Control Sphere

*
  • H
Buffer Overflow

*
  • M
Improper Input Validation

*
  • H
Improper Authentication

*
  • H
Improper Authentication

*
  • H
Improper Authentication

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • L
Improper Handling of Inconsistent Structural Elements

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Reliance on Cookies without Validation and Integrity Checking in a Security Decision

*
  • M
Expected Behavior Violation

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
The UI Performs the Wrong Action

*
  • H
Information Exposure

*
  • H
Buffer Overflow

*
  • H
Product UI does not Warn User of Unsafe Actions

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Buffer Overflow

*
  • L
Use After Free

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Cross-site Scripting (XSS)

*
  • H
Buffer Overflow

*
  • M
Insufficient UI Warning of Dangerous Operations

*
  • M
Return of Wrong Status Code

*
  • M
Integer Overflow or Wraparound

*
  • H
Buffer Overflow

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Cross-site Scripting (XSS)

*
  • H
Use After Free

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • H
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • H
Buffer Overflow

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Use of Uninitialized Variable

*
  • H
Buffer Overflow

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Inclusion of Functionality from Untrusted Control Sphere

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • C
Buffer Overflow

*
  • M
Improper Use of Validation Framework

*
  • L
Information Exposure

*
  • H
Buffer Overflow

*
  • H
Exposure of System Data to an Unauthorized Control Sphere

*
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Improper Preservation of Permissions

*
  • M
Improper Certificate Validation

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • H
Buffer Overflow

*
  • M
Use After Free

*
  • L
Resource Exhaustion

*
  • M
Use After Free

*
  • H
Use After Free

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Improper Preservation of Permissions

*
  • H
The UI Performs the Wrong Action

*
  • H
Use After Free

*
  • H
Incorrect Behavior Order: Early Validation

*
  • C
Use After Free

*
  • C
Use After Free

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • H
Buffer Overflow

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Arbitrary Code Injection

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Incorrect Calculation

*
  • M
Integer Overflow or Wraparound

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Buffer Overflow

*
  • H
Buffer Overflow

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • L
NULL Pointer Dereference

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Cross-site Scripting (XSS)

*
  • L
Improper Preservation of Permissions

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Buffer Overflow

*
  • M
Unquoted Search Path or Element

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Information Exposure

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Use After Free

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Inclusion of Functionality from Untrusted Control Sphere

*
  • H
Incorrect Permission Assignment for Critical Resource

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Use After Free

*
  • H
Cleartext Transmission of Sensitive Information

*
  • H
Buffer Overflow

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • M
Use After Free

*
  • M
Out-of-Bounds

*
  • H
Buffer Overflow

*
  • H
Cross-site Scripting (XSS)

*
  • H
Out-of-Bounds

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Use After Free

*
  • H
Use of Uninitialized Resource

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • H
Use After Free

<0:60.5.0-1.el6_10
  • H
Use After Free

<0:60.4.0-1.el6
  • H
Buffer Overflow

<0:60.5.0-1.el6_10
  • H
Improper Authentication

<0:60.5.0-1.el6_10
  • H
Use After Free

<0:60.5.0-1.el6_10
  • H
Buffer Overflow

<0:60.4.0-1.el6
  • H
Out-of-bounds Read

<0:60.4.0-1.el6
  • H
Integer Overflow or Wraparound

<0:60.4.0-1.el6
  • H
Buffer Overflow

<0:60.4.0-1.el6
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.4.0-1.el6
  • M
Buffer Overflow

*
  • H
Buffer Overflow

<0:60.3.0-1.el6
  • H
Buffer Overflow

<0:60.3.0-1.el6
  • H
Improper Input Validation

<0:60.2.1-5.el6
  • H
Information Exposure

<0:60.2.1-5.el6
  • H
Integer Overflow or Wraparound

<0:60.3.0-1.el6
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.2.1-5.el6
  • H
Out-of-bounds Write

<0:60.2.1-5.el6
  • H
Buffer Overflow

<0:60.2.1-5.el6
  • H
Use After Free

<0:60.2.1-5.el6
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:52.9.1-1.el6
  • H
Race Condition

<0:60.3.0-1.el6
  • H
Information Exposure

<0:52.8.0-2.el6_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:52.9.1-1.el6
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:52.9.1-1.el6
  • H
Buffer Overflow

<0:52.9.1-1.el6
  • H
Files or Directories Accessible to External Parties

<0:52.9.1-1.el6
  • H
Use After Free

<0:52.8.0-2.el6_9
  • H
Buffer Overflow

<0:52.9.1-1.el6
  • H
Use After Free

<0:60.2.1-5.el6
  • H
Information Exposure

<0:52.8.0-2.el6_9
  • H
Improper Input Validation

<0:52.8.0-2.el6_9
  • H
Information Exposure

<0:52.8.0-2.el6_9
  • H
Use After Free

<0:52.9.1-1.el6
  • H
Improper Input Validation

<0:52.8.0-2.el6_9
  • H
Buffer Overflow

<0:52.8.0-2.el6_9
  • H
Use After Free

<0:52.8.0-2.el6_9
  • H
Information Exposure

<0:52.9.1-1.el6
  • H
Integer Overflow or Wraparound

<0:52.9.1-1.el6
  • H
Out-of-bounds Read

<0:52.9.1-1.el6
  • H
Use After Free

<0:52.9.1-1.el6
  • H
Buffer Overflow

<0:52.8.0-2.el6_9
  • H
Buffer Overflow

<0:52.8.0-2.el6_9
  • H
Integer Overflow or Wraparound

<0:52.8.0-2.el6_9
  • H
Missing Authorization

<0:52.8.0-2.el6_9
  • H
CVE-2014-1518

<0:24.5.0-1.el6_5
  • H
Buffer Overflow

<0:24.5.0-1.el6_5
  • H
Use After Free

<0:24.5.0-1.el6_5
  • H
Cross-site Scripting (XSS)

<0:24.5.0-1.el6_5
  • H
Integer Overflow or Wraparound

<0:52.7.0-1.el6_9
  • H
Use After Free

<0:24.5.0-1.el6_5
  • H
Buffer Overflow

<0:52.7.0-1.el6_9
  • H
Out-of-bounds Read

<0:24.5.0-1.el6_5
  • H
Improper Privilege Management

<0:24.5.0-1.el6_5
  • H
Heap-based Buffer Overflow

<0:52.7.0-1.el6_9
  • H
Out-of-bounds Write

<0:52.7.0-1.el6_9
  • H
Buffer Overflow

<0:52.7.0-1.el6_9
  • H
Buffer Overflow

<0:52.7.0-1.el6_9
  • H
Information Exposure

<0:52.5.2-1.el6_9
  • H
Improper Privilege Management

<0:24.4.0-1.el6_5
  • H
Arbitrary Code Injection

<0:52.5.2-1.el6_9
  • H
Use After Free

<0:24.4.0-1.el6_5
  • H
Use After Free

<0:52.6.0-1.el6_9
  • H
Use After Free

<0:52.6.0-1.el6_9
  • H
Information Exposure

<0:24.4.0-1.el6_5
  • H
Buffer Overflow

<0:52.6.0-1.el6_9
  • H
Integer Overflow or Wraparound

<0:52.6.0-1.el6_9
  • H
Out-of-bounds Read

<0:24.4.0-1.el6_5
  • H
Improper Privilege Management

<0:24.4.0-1.el6_5
  • H
Out-of-bounds Read

<0:24.4.0-1.el6_5
  • H
Buffer Overflow

<0:24.4.0-1.el6_5
  • H
Out-of-bounds Write

<0:24.4.0-1.el6_5
  • H
Use After Free

<0:52.6.0-1.el6_9
  • H
Use After Free

<0:52.6.0-1.el6_9
  • H
Improper Input Validation

<0:52.5.2-1.el6_9
  • H
Out-of-bounds Read

<0:24.4.0-1.el6_5
  • H
Out-of-Bounds

<0:24.4.0-1.el6_5
  • H
Buffer Overflow

<0:52.5.0-1.el6_9
  • H
Use After Free

<0:52.6.0-1.el6_9
  • H
Use After Free

<0:52.6.0-1.el6_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:52.6.0-1.el6_9
  • H
Use After Free

<0:52.6.0-1.el6_9
  • H
Information Exposure

<0:24.3.0-2.el6_5
  • H
Information Exposure

<0:52.5.0-1.el6_9
  • H
Use After Free

<0:52.5.0-1.el6_9
  • H
CVE-2014-1477

<0:24.3.0-2.el6_5
  • H
Use After Free

<0:24.3.0-2.el6_5
  • H
Out-of-bounds Write

<0:24.3.0-2.el6_5
  • H
Arbitrary Code Injection

<0:52.5.2-1.el6_9
  • H
Cross-site Scripting (XSS)

<0:24.2.0-1.el6_5
  • H
Arbitrary Code Injection

<0:24.2.0-1.el6_5
  • H
Cross-site Scripting (XSS)

<0:24.2.0-1.el6_5
  • H
CVE-2013-5609

<0:24.2.0-1.el6_5
  • H
Use After Free

<0:24.2.0-1.el6_5
  • H
Buffer Overflow

<0:52.4.0-2.el6_9
  • H
Use After Free

<0:52.4.0-2.el6_9
  • H
Use After Free

<0:52.4.0-2.el6_9
  • H
Download of Code Without Integrity Check

<0:52.4.0-2.el6_9
  • H
Buffer Overflow

<0:52.4.0-2.el6_9
  • H
Incorrect Authorization

<0:52.3.0-1.el6_9
  • H
Out-of-bounds Read

<0:24.2.0-1.el6_5
  • H
Use After Free

<0:24.2.0-1.el6_5
  • H
Use After Free

<0:52.3.0-1.el6_9
  • H
CVE-2014-1481

<0:24.3.0-2.el6_5
  • H
CVE-2014-1479

<0:24.3.0-2.el6_5
  • H
Out-of-Bounds

<0:52.3.0-1.el6_9
  • H
Use After Free

<0:52.3.0-1.el6_9
  • H
Use After Free

<0:52.4.0-2.el6_9
  • H
Cross-site Scripting (XSS)

<0:52.4.0-2.el6_9
  • H
Use After Free

<0:52.3.0-1.el6_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:52.3.0-1.el6_9
  • H
Use After Free

<0:52.3.0-1.el6_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:52.3.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.3.0-1.el6_9
  • H
Incorrect Authorization

<0:52.3.0-1.el6_9
  • H
Use After Free

<0:24.2.0-1.el6_5
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:24.2.0-1.el6_5
  • H
Out-of-bounds Read

<0:52.3.0-1.el6_9
  • H
Use After Free

<0:52.3.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.3.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.3.0-1.el6_9
  • H
Out-of-Bounds

<0:17.0.10-1.el6_4
  • H
Use After Free

<0:17.0.10-1.el6_4
  • H
CVE-2013-5590

<0:17.0.10-1.el6_4
  • H
Out-of-Bounds

<0:17.0.10-1.el6_4
  • H
Use After Free

<0:17.0.10-1.el6_4
  • H
Use After Free

<0:17.0.10-1.el6_4
  • H
Use After Free

<0:17.0.10-1.el6_4
  • H
Out-of-Bounds

<0:17.0.10-1.el6_4
  • H
Out-of-Bounds

<0:17.0.9-1.el6_4
  • H
Cross-site Scripting (XSS)

<0:17.0.8-5.el6_4
  • H
Access Restriction Bypass

<0:17.0.8-5.el6_4
  • H
CVE-2013-1701

<0:17.0.8-5.el6_4
  • H
Cross-site Scripting (XSS)

<0:17.0.8-5.el6_4
  • H
Out-of-Bounds

<0:17.0.9-1.el6_4
  • H
Out-of-Bounds

<0:17.0.9-1.el6_4
  • H
Access Restriction Bypass

<0:17.0.9-1.el6_4
  • H
Out-of-Bounds

<0:17.0.9-1.el6_4
  • H
Out-of-Bounds

<0:17.0.9-1.el6_4
  • H
Use After Free

<0:17.0.9-1.el6_4
  • H
Improper Input Validation

<0:17.0.9-1.el6_4
  • H
Access Restriction Bypass

<0:17.0.8-5.el6_4
  • H
Access Restriction Bypass

<0:17.0.8-5.el6_4
  • H
Access Restriction Bypass

<0:17.0.7-1.el6_4
  • H
Out-of-Bounds

<0:17.0.7-1.el6_4
  • H
Improper Input Validation

<0:17.0.7-1.el6_4
  • H
CVE-2013-1682

<0:17.0.7-1.el6_4
  • H
Cross-site Request Forgery (CSRF)

<0:17.0.7-1.el6_4
  • H
Access Restriction Bypass

<0:17.0.7-1.el6_4
  • H
Access Restriction Bypass

<0:17.0.7-1.el6_4
  • H
Resource Management Errors

<0:17.0.7-1.el6_4
  • H
Use After Free

<0:78.4.3-1.el6_10
  • H
Use After Free

<0:52.2.0-1.el6_9
  • H
Resource Management Errors

<0:17.0.7-1.el6_4
  • H
Heap-based Buffer Overflow

<0:52.2.0-1.el6_9
  • H
Heap-based Buffer Overflow

<0:52.2.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.2.0-1.el6_9
  • H
Out-of-Bounds

<0:52.2.0-1.el6_9
  • H
Use After Free

<0:52.2.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.2.0-1.el6_9
  • H
Use After Free

<0:52.2.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.2.0-1.el6_9
  • H
Missing Initialization of a Variable

<0:52.2.0-1.el6_9
  • H
Resource Management Errors

<0:17.0.7-1.el6_4
  • H
Out-of-bounds Write

<0:52.1.0-1.el6_9
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:78.5.0-1.el6_10
  • H
Improper Validation of Integrity Check Value

<0:78.5.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:78.5.0-1.el6_10
  • H
Buffer Overflow

<0:78.5.0-1.el6_10
  • H
Improperly Implemented Security Check for Standard

<0:78.5.0-1.el6_10
  • H
Use After Free

<0:78.5.0-1.el6_10
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:78.5.0-1.el6_10
  • H
Use After Free

<0:52.2.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.2.0-1.el6_9
  • H
Reachable Assertion

<0:52.2.0-1.el6_9
  • H
Out-of-Bounds

<0:52.2.0-1.el6_9
  • H
Out-of-Bounds

<0:52.1.0-1.el6_9
  • H
Improper Input Validation

<0:52.2.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.2.0-1.el6_9
  • H
Use After Free

<0:52.2.0-1.el6_9
  • H
Use After Free

<0:52.2.0-1.el6_9
  • H
Access Restriction Bypass

<0:17.0.6-2.el6_4
  • H
Resource Management Errors

<0:17.0.6-2.el6_4
  • H
Use After Free

<0:52.2.0-1.el6_9
  • H
Resource Management Errors

<0:17.0.6-2.el6_4
  • H
Resource Management Errors

<0:17.0.6-2.el6_4
  • H
Out-of-Bounds

<0:52.1.0-1.el6_9
  • H
Missing Initialization of a Variable

<0:17.0.6-2.el6_4
  • H
CVE-2013-0801

<0:17.0.6-2.el6_4
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Out-of-Bounds

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Improper Input Validation

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:17.0.6-2.el6_4
  • H
Out-of-bounds Write

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Out-of-Bounds

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.1.0-1.el6_9
  • H
Out-of-Bounds

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:78.5.0-1.el6_10
  • H
Cross-site Scripting (XSS)

<0:78.5.0-1.el6_10
  • H
Cross-site Scripting (XSS)

<0:78.5.0-1.el6_10
  • H
Out-of-Bounds

<0:17.0.6-2.el6_4
  • H
Out-of-Bounds

<0:17.0.6-2.el6_4
  • H
Out-of-Bounds

<0:17.0.6-2.el6_4
  • H
Out-of-bounds Read

<0:52.1.0-1.el6_9
  • H
Out-of-Bounds

<0:52.1.0-1.el6_9
  • H
Information Exposure

<0:52.1.0-1.el6_9
  • H
Improper Validation of Array Index

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Stack-based Buffer Overflow

<0:52.1.0-1.el6_9
  • H
Improper Input Validation

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:52.1.0-1.el6_9
  • H
Out-of-Bounds

<0:45.8.0-1.el6_8
  • H
Out-of-Bounds

<0:45.8.0-1.el6_8
  • H
Error Handling

<0:45.8.0-1.el6_8
  • H
Use After Free

<0:45.8.0-1.el6_8
  • H
Cross-site Scripting (XSS)

<0:52.1.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.1.0-1.el6_9
  • H
Out-of-bounds Read

<0:52.1.0-1.el6_9
  • H
Use After Free

<0:45.5.1-1.el6_8
  • H
CVE-2013-0788

<0:17.0.5-1.el6_4
  • H
Information Exposure

<0:45.8.0-1.el6_8
  • H
Improper Input Validation

<0:45.7.0-1.el6_8
  • H
CVE-2017-5390

<0:45.7.0-1.el6_8
  • H
Information Exposure

<0:45.8.0-1.el6_8
  • H
Out-of-Bounds

<0:45.8.0-1.el6_8
  • H
Out-of-Bounds

<0:45.7.0-1.el6_8
  • H
Use After Free

<0:45.7.0-1.el6_8
  • H
DEPRECATED: Use of Uninitialized Resource

<0:45.8.0-1.el6_8
  • H
Use After Free

<0:45.8.0-1.el6_8
  • H
Improper Input Validation

<0:45.6.0-1.el6_8
  • H
Security Features

<0:45.6.0-1.el6_8
  • H
Out-of-Bounds

<0:45.5.0-1.el6_8
  • H
Use After Free

<0:45.7.0-1.el6_8
  • H
Use After Free

<0:45.7.0-1.el6_8
  • H
Out-of-bounds Write

<0:17.0.5-1.el6_4
  • H
CVE-2013-0796

<0:17.0.5-1.el6_4
  • H
Information Exposure

<0:45.7.0-1.el6_8
  • H
Access Restriction Bypass

<0:17.0.5-1.el6_4
  • H
Out-of-Bounds

<0:45.7.0-1.el6_8
  • H
Cross-site Scripting (XSS)

<0:17.0.5-1.el6_4
  • H
Use After Free

<0:45.6.0-1.el6_8
  • H
Origin Validation Error

<0:45.6.0-1.el6_8
  • H
Security Features

<0:45.6.0-1.el6_8
  • H
Out-of-Bounds

<0:45.6.0-1.el6_8
  • H
Improper Access Control

<0:45.6.0-1.el6_8
  • H
Use After Free

<0:17.0.3-2.el6_4
  • C
CVE-2013-0783

<0:17.0.3-1.el6_3
  • C
Out-of-bounds Read

<0:17.0.3-1.el6_3
  • C
Improper Certificate Validation

<0:17.0.3-1.el6_3
  • C
Use After Free

<0:17.0.3-1.el6_3
  • C
Out-of-bounds Read

<0:17.0.3-1.el6_3
  • H
Out-of-Bounds

<0:45.4.0-1.el6_8
  • C
Use After Free

<0:10.0.12-3.el6_3
  • C
Use After Free

<0:10.0.12-3.el6_3
  • C
Improper Authentication

<0:10.0.12-3.el6_3
  • C
Use After Free

<0:10.0.12-3.el6_3
  • C
Use After Free

<0:10.0.12-3.el6_3
  • C
Use After Free

<0:10.0.12-3.el6_3
  • C
CVE-2013-0769

<0:10.0.12-3.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.11-1.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.11-1.el6_3
  • H
Out-of-Bounds

<0:45.3.0-1.el6_8
  • C
CVE-2013-0746

<0:10.0.12-3.el6_3
  • C
Integer Overflow or Wraparound

<0:10.0.12-3.el6_3
  • C
Arbitrary Code Injection

<0:10.0.12-3.el6_3
  • C
Use After Free

<0:10.0.12-3.el6_3
  • C
Information Exposure

<0:10.0.12-3.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.11-1.el6_3
  • C
Out-of-bounds Write

<0:10.0.11-1.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • C
CVE-2012-5842

<0:10.0.11-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.11-1.el6_3
  • C
Use After Free

<0:10.0.11-1.el6_3
  • H
Arbitrary Code Injection

<0:10.0.10-1.el6_3
  • H
Out-of-Bounds

<0:45.2-1.el6_8
  • H
Cross-site Scripting (XSS)

<0:10.0.10-1.el6_3
  • H
Cross-site Scripting (XSS)

<0:10.0.10-1.el6_3
  • C
Out-of-bounds Read

<0:10.0.8-1.el6_3
  • C
Out-of-bounds Read

<0:10.0.8-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.8-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.8-1.el6_3
  • C
Improper Input Validation

<0:10.0.8-1.el6_3
  • C
Improper Privilege Management

<0:10.0.8-1.el6_3
  • C
Out-of-bounds Read

<0:10.0.8-1.el6_3
  • C
Access Restriction Bypass

<0:10.0.8-1.el6_3
  • C
Out-of-bounds Read

<0:10.0.8-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.8-1.el6_3
  • C
CVE-2012-3982

<0:10.0.8-1.el6_3
  • H
Out-of-Bounds

<0:38.8.0-2.el6_8
  • C
Out-of-bounds Read

<0:10.0.7-1.el6_3
  • C
Out-of-Bounds

<0:10.0.7-1.el6_3
  • C
Out-of-Bounds

<0:10.0.7-1.el6_3
  • C
Out-of-Bounds

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Origin Validation Error

<0:10.0.8-2.el6_3
  • H
Out-of-Bounds

<0:38.8.0-2.el6_8
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Out-of-bounds Read

<0:10.0.8-1.el6_3
  • C
Out-of-Bounds

<0:10.0.8-1.el6_3
  • C
Access Restriction Bypass

<0:10.0.7-1.el6_3
  • C
Out-of-Bounds

<0:10.0.8-1.el6_3
  • C
Out-of-Bounds

<0:10.0.8-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.8-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.8-1.el6_3
  • C
Out-of-Bounds

<0:10.0.8-1.el6_3
  • C
Use After Free

<0:10.0.8-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Arbitrary Code Injection

<0:10.0.7-1.el6_3
  • C
Out-of-bounds Read

<0:10.0.8-1.el6_3
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
Improper Data Handling

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • C
Resource Management Errors

<0:10.0.6-1.el6_3
  • H
CVE-2016-1966

<0:38.7.0-1.el6_7
  • H
Improper Data Handling

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • C
CVE-2012-1967

<0:10.0.6-1.el6_3
  • H
CVE-2016-1961

<0:38.7.0-1.el6_7
  • C
Use After Free

<0:10.0.7-1.el6_3
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
Access Restriction Bypass

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
CVE-2016-1964

<0:38.7.0-1.el6_7
  • C
Resource Management Errors

<0:10.0.6-1.el6_3
  • C
CVE-2012-1964

<0:10.0.6-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • C
Use After Free

<0:10.0.7-1.el6_3
  • H
CVE-2016-1960

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Out-of-Bounds

<0:10.0.7-1.el6_3
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • C
Use After Free

<0:10.0.7-1.el6_3
  • H
Heap-based Buffer Overflow

<0:38.6.0-1.el6_7
  • H
Out-of-bounds Read

<0:38.6.0-1.el6_7
  • H
NULL Pointer Dereference

<0:38.6.0-1.el6_7
  • H
Out-of-Bounds

<0:38.6.0-1.el6_7
  • C
Resource Management Errors

<0:10.0.6-1.el6_3
  • C
Access Restriction Bypass

<0:10.0.6-1.el6_3
  • C
Cross-site Scripting (XSS)

<0:10.0.6-1.el6_3
  • C
Out-of-Bounds

<0:10.0.6-1.el6_3
  • C
Use After Free

<0:10.0.6-1.el6_3
  • C
CVE-2012-1948

<0:10.0.6-1.el6_3
  • C
CVE-2012-1955

<0:10.0.6-1.el6_3
  • C
Improper Input Validation

<0:10.0.6-1.el6_3
  • H
Open Redirect

<0:78.3.1-1.el6_10
  • C
Resource Management Errors

<0:10.0.6-1.el6_3
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • C
Access Restriction Bypass

<0:10.0.6-1.el6_3
  • H
Out-of-Bounds

<0:38.7.0-1.el6_7
  • H
Use After Free

<0:78.3.1-1.el6_10
  • H
Cross-site Scripting (XSS)

<0:78.3.1-1.el6_10
  • H
Buffer Overflow

<0:78.4.0-1.el6_10
  • H
Use After Free

<0:78.4.0-1.el6_10
  • H
Out-of-Bounds

<0:38.6.0-1.el6_7
  • H
Out-of-Bounds

<0:38.5.0-1.el6_7
  • C
Use After Free

<0:10.0.5-2.el6_2
  • C
Use After Free

<0:10.0.5-2.el6_2
  • C
CVE-2012-1938

<0:10.0.5-2.el6_2
  • C
CVE-2012-1937

<0:10.0.5-2.el6_2
  • C
CVE-2011-3101

<0:10.0.5-2.el6_2
  • H
Buffer Overflow

<0:78.3.1-1.el6_10
  • H
Information Exposure

<0:38.5.0-1.el6_7
  • H
Integer Overflow or Wraparound

<0:38.5.0-1.el6_7
  • H
Numeric Errors

<0:38.5.0-1.el6_7
  • H
Integer Overflow or Wraparound

<0:38.5.0-1.el6_7
  • C
Information Exposure

<0:10.0.5-2.el6_2
  • C
Out-of-Bounds

<0:10.0.5-2.el6_2
  • C
Use After Free

<0:10.0.5-2.el6_2
  • C
Use After Free

<0:10.0.5-2.el6_2
  • C
Cross-site Scripting (XSS)

<0:10.0.5-2.el6_2
  • C
Out-of-Bounds

<0:10.0.5-2.el6_2
  • C
Cross-site Scripting (XSS)

<0:10.0.4-1.el6_2
  • C
Access Restriction Bypass

<0:10.0.4-1.el6_2
  • C
CVE-2012-0467

<0:10.0.4-1.el6_2
  • C
CVE-2012-0479

<0:10.0.4-1.el6_2
  • C
Off-by-one Error

<0:10.0.4-1.el6_2
  • C
Cross-site Scripting (XSS)

<0:10.0.4-1.el6_2
  • C
Information Exposure

<0:10.0.3-1.el6_2
  • C
Out-of-Bounds

<0:10.0.4-1.el6_2
  • C
Cross-site Scripting (XSS)

<0:10.0.4-1.el6_2
  • C
Numeric Errors

<0:10.0.4-1.el6_2
  • C
Out-of-Bounds

<0:10.0.4-1.el6_2
  • C
Use After Free

<0:10.0.4-1.el6_2
  • C
Out-of-Bounds

<0:10.0.4-1.el6_2
  • C
Resource Management Errors

<0:10.0.3-1.el6_2
  • C
Heap-based Buffer Overflow

<0:3.1.18-2.el6_2
  • C
Resource Management Errors

<0:10.0.3-1.el6_2
  • C
Access Restriction Bypass

<0:10.0.3-1.el6_2
  • C
Cross-site Scripting (XSS)

<0:10.0.3-1.el6_2
  • C
CVE-2012-0462

<0:10.0.3-1.el6_2
  • C
Cross-site Scripting (XSS)

<0:10.0.3-1.el6_2
  • C
Out-of-Bounds

<0:3.1.18-1.el6_2
  • C
Access Restriction Bypass

<0:10.0.3-1.el6_2
  • C
CVE-2012-0461

<0:10.0.3-1.el6_2
  • C
Access Restriction Bypass

<0:10.0.3-1.el6_2
  • H
Code

<0:38.4.0-1.el6_7
  • C
Use After Free

<0:3.1.18-1.el6_2
  • H
Out-of-Bounds

<0:38.4.0-1.el6_7
  • H
Security Features

<0:38.4.0-1.el6_7
  • H
Use After Free

<0:68.12.0-1.el6_10
  • H
Access Restriction Bypass

<0:38.4.0-1.el6_7
  • H
Out-of-Bounds

<0:38.4.0-1.el6_7
  • H
Out-of-Bounds

<0:38.4.0-1.el6_7
  • C
CVE-2012-0442

<0:3.1.18-1.el6_2
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • C
Information Exposure

<0:3.1.18-1.el6_2
  • H
Use After Free

<0:68.11.0-1.el6_10
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • H
Use After Free

<0:38.3.0-1.el6_7
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • H
Information Exposure

<0:38.3.0-1.el6_7
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • H
Improper Access Control

<0:38.3.0-1.el6_7
  • H
Out-of-Bounds

<0:38.4.0-1.el6_7
  • H
Information Exposure

<0:68.10.0-1.el6_10
  • C
Out-of-Bounds

<0:3.1.16-2.el6_1
  • H
Incorrect Use of Privileged APIs

<0:68.12.0-1.el6_10
  • H
Improper Following of a Certificate's Chain of Trust

<0:68.10.0-1.el6_10
  • H
Buffer Overflow

<0:68.11.0-1.el6_10
  • H
Information Exposure

<0:68.11.0-1.el6_10
  • H
Out-of-Bounds

<0:38.2.0-4.el6_7
  • H
CVE-2020-6514

<0:68.11.0-1.el6_10
  • H
Out-of-Bounds

<0:38.2.0-4.el6_7
  • H
Buffer Access with Incorrect Length Value

<0:38.3.0-1.el6_7
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • C
Cross-site Scripting (XSS)

<0:3.1.16-2.el6_1
  • C
Improper Input Validation

<0:3.1.16-2.el6_1
  • H
Execution with Unnecessary Privileges

<0:38.3.0-1.el6_7
  • H
CVE-2015-4488

<0:38.2.0-4.el6_7
  • H
Information Exposure

<0:68.10.0-1.el6_10
  • H
Use After Free

<0:31.8.0-1.el6_6
  • H
Heap-based Buffer Overflow

<0:38.2.0-4.el6_7
  • C
Arbitrary Code Injection

<0:3.1.15-1.el6_1
  • C
Access Restriction Bypass

<0:3.1.15-1.el6_1
  • H
Out-of-Bounds

<0:38.2.0-4.el6_7
  • C
Cross-site Scripting (XSS)

<0:3.1.15-1.el6_1
  • H
Out-of-Bounds

<0:31.8.0-1.el6_6
  • H
Code

<0:31.8.0-1.el6_6
  • C
CVE-2011-2995

<0:3.1.15-1.el6_1
  • C
Use After Free

<0:68.8.0-1.el6_10
  • C
Integer Overflow or Wraparound

<0:3.1.15-1.el6_1
  • H
Code

<0:31.8.0-1.el6_6
  • H
Out-of-Bounds

<0:31.8.0-1.el6_6
  • H
Cryptographic Issues

<0:31.8.0-1.el6_6
  • H
Use After Free

<0:68.9.0-1.el6_10
  • H
Out-of-Bounds

<0:31.8.0-1.el6_6
  • H
Code

<0:31.8.0-1.el6_6
  • H
Buffer Overflow

<0:68.9.0-1.el6_10
  • C
Encoding Error

<0:68.8.0-1.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:68.9.0-1.el6_10
  • C
Files or Directories Accessible to External Parties

<0:68.8.0-1.el6_10
  • C
CVE-2011-2982

<0:3.1.12-1.el6_1
  • C
Arbitrary Code Injection

<0:3.1.12-1.el6_1
  • M
Arbitrary Code Injection

*
  • H
Use After Free

<0:68.10.0-1.el6_10
  • H
Use After Free

<0:68.10.0-1.el6_10
  • H
Out-of-Bounds

<0:31.8.0-1.el6_6
  • C
Buffer Overflow

<0:68.8.0-1.el6_10
  • C
Buffer Overflow

<0:68.8.0-1.el6_10
  • C
Use After Free

*
  • C
CVE-2011-2376

<0:3.1.11-2.el6_1
  • H
Code

<0:31.8.0-1.el6_6
  • H
Code

<0:31.8.0-1.el6_6
  • C
Resource Management Errors

<0:3.1.11-2.el6_1
  • C
CVE-2011-2364

<0:3.1.11-2.el6_1
  • C
CVE-2011-2365

<0:3.1.11-2.el6_1
  • H
Information Exposure

<0:68.9.0-1.el6_10
  • C
Resource Management Errors

<0:3.1.11-2.el6_1
  • C
Arbitrary Code Injection

<0:3.1.12-1.el6_1
  • C
CVE-2011-2374

<0:3.1.11-2.el6_1
  • C
CVE-2011-2375

<0:3.1.11-2.el6_1
  • C
Arbitrary Code Injection

<0:3.1.11-2.el6_1
  • C
Out-of-Bounds

<0:3.1.11-2.el6_1
  • C
Access Restriction Bypass

<0:3.1.11-2.el6_1
  • C
Integer Overflow or Wraparound

*
  • C
Resource Management Errors

<0:3.1.11-2.el6_1
  • C
CVE-2011-0081

<0:3.1.10-1.el6_0
  • H
CVE-2015-2708

<0:31.7.0-1.el6_6
  • C
CVE-2011-0070

<0:3.1.10-1.el6_0
  • C
CVE-2011-0080

<0:3.1.10-1.el6_0
  • C
CVE-2011-0075

<0:3.1.10-1.el6_0
  • C
CVE-2011-0074

<0:3.1.10-1.el6_0
  • C
Improper Input Validation

<0:3.1.10-1.el6_0
  • H
Out-of-Bounds

<0:31.7.0-1.el6_6
  • H
Out-of-Bounds

<0:31.7.0-1.el6_6
  • H
Use After Free

<0:31.7.0-1.el6_6
  • H
Heap-based Buffer Overflow

<0:31.6.0-1.el6_6
  • C
Improper Input Validation

<0:3.1.8-4.el6_0
  • C
Integer Overflow or Wraparound

<0:3.1.10-1.el6_0
  • C
CVE-2011-0078

<0:3.1.10-1.el6_0
  • C
Directory Traversal

<0:3.1.10-1.el6_0
  • C
CVE-2011-0053

<0:3.1.8-4.el6_0
  • H
Cross-site Request Forgery (CSRF)

<0:31.6.0-1.el6_6
  • H
Use After Free

<0:31.6.0-1.el6_6
  • H
Execution with Unnecessary Privileges

<0:31.6.0-1.el6_6
  • H
Improperly Implemented Security Check for Standard

<0:31.6.0-1.el6_6
  • C
CVE-2011-0062

<0:3.1.8-4.el6_0
  • C
Out-of-Bounds

<0:3.1.8-4.el6_0
  • H
Out-of-Bounds

<0:31.5.0-1.el6_6
  • H
CVE-2015-0836

<0:31.5.0-1.el6_6
  • H
Information Exposure

<0:31.5.0-1.el6_6
  • H
Use After Free

<0:31.5.0-1.el6_6
  • H
Buffer Overflow

<0:31.3.0-1.el6_6
  • H
Cross-site Request Forgery (CSRF)

<0:31.4.0-1.el6_6
  • H
Arbitrary Argument Injection

<0:31.4.0-1.el6_6
  • H
Exposed Dangerous Method or Function

<0:31.3.0-1.el6_6
  • H
Buffer Overflow

<0:31.3.0-1.el6_6
  • H
Heap-based Buffer Overflow

<0:31.4.0-1.el6_6
  • H
Improper Input Validation

<0:31.3.0-1.el6_6
  • H
Use After Free

<0:31.3.0-1.el6_6
  • H
Out-of-bounds Write

<0:31.2.0-3.el6_6
  • M
Out-of-Bounds

<0:3.1.7-3.el6_0
  • M
Out-of-Bounds

<0:3.1.6-1.el6_0
  • M
Access Restriction Bypass

<0:3.1.6-1.el6_0
  • H
Use After Free

<0:31.2.0-3.el6_6
  • H
CVE-2014-1577

<0:31.2.0-3.el6_6
  • H
CVE-2014-1574

<0:31.2.0-3.el6_6
  • M
Out-of-Bounds

*
  • H
Out-of-Bounds

<0:24.8.0-1.el6_5
  • H
Use After Free

<0:24.8.0-1.el6_5
  • M
Out-of-Bounds

<0:3.1.7-3.el6_0
  • M
Improper Input Validation

<0:3.1.7-3.el6_0
  • M
Out-of-Bounds

<0:3.1.6-1.el6_0
  • M
Out-of-Bounds

<0:3.1.6-1.el6_0
  • M
Use After Free

<0:3.1.6-1.el6_0
  • M
CVE-2010-3182

<0:3.1.6-1.el6_0
  • M
CVE-2010-3175

<0:3.1.6-1.el6_0
  • M
CVE-2010-3176

<0:3.1.6-1.el6_0
  • H
Arbitrary Code Injection

<0:24.7.0-1.el6_5
  • H
Use After Free

*
  • H
Out-of-bounds Write

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
NULL Pointer Dereference

*
  • M
Arbitrary Argument Injection

*
  • H
Operation on a Resource after Expiration or Release

<0:24.7.0-1.el6_5
  • M
Information Exposure

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • L
Integer Overflow or Wraparound

*
  • L
Information Exposure

*
  • M
Null Byte Interaction Error (Poison Null Byte)

*
  • M
Improper Preservation of Permissions

*
  • H
Use After Free

<0:24.6.0-1.el6_5
  • H
Use After Free

<0:68.7.0-1.el6_10
  • H
Buffer Overflow

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Use After Free

<0:68.7.0-1.el6_10
  • M
Improper Preservation of Permissions

*
  • H
Buffer Overflow

*
  • M
Insufficiently Protected Credentials

*
  • L
Untrusted Search Path

*
  • H
Improper Input Validation

<0:68.6.0-1.el6_10
  • M
Out-of-bounds Read

*
  • H
NULL Pointer Dereference

<0:68.5.0-1.el6_10
  • H
Out-of-Bounds

<0:68.7.0-1.el6_10
  • H
Use After Free

<0:24.7.0-1.el6_5
  • H
CVE-2014-1547

<0:24.7.0-1.el6_5
  • H
CVE-2014-1533

<0:24.6.0-1.el6_5
  • H
Use After Free

<0:24.6.0-1.el6_5
  • H
Inclusion of Functionality from Untrusted Control Sphere

*
  • H
Out-of-bounds Read

*
  • H
Buffer Overflow

*
  • H
Information Exposure

<0:68.6.0-1.el6_10
  • M
Information Exposure

*
  • H
Out-of-bounds Read

<0:68.6.0-1.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Use After Free

<0:68.6.0-1.el6_10
  • H
Buffer Overflow

<0:68.6.0-1.el6_10
  • L
Insufficiently Protected Credentials

*
  • H
Buffer Overflow

*
  • H
Out-of-Bounds

<0:68.7.0-1.el6_10
  • H
Buffer Overflow

<0:68.7.0-1.el6_10
  • M
Improper Verification of Cryptographic Signature

*
  • H
Use After Free

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Out-of-bounds Write

*
  • H
Information Exposure

*
  • H
Buffer Overflow

*
  • H
Information Exposure

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Cross-site Scripting (XSS)

<0:68.5.0-1.el6_10
  • H
Out-of-bounds Read

<0:68.5.0-1.el6_10
  • H
Cleartext Storage of Sensitive Information

<0:68.5.0-1.el6_10
  • H
Buffer Overflow

*
  • H
Cross-site Scripting (XSS)

<0:68.4.1-2.el6_10
  • H
Use After Free

<0:68.6.0-1.el6_10
  • H
Out-of-bounds Read

<0:68.6.0-1.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:68.4.1-2.el6_10
  • H
Missing Initialization of a Variable

<0:68.5.0-1.el6_10
  • H
Buffer Overflow

<0:68.5.0-1.el6_10
  • H
Cross-site Scripting (XSS)

<0:68.4.1-2.el6_10
  • L
Information Exposure

*
  • H
Buffer Overflow

<0:68.4.1-2.el6_10
  • H
Stack-based Buffer Overflow

*
  • H
Buffer Overflow

<0:68.3.0-3.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:68.4.1-2.el6_10
  • M
Information Exposure

*
  • H
Use After Free

<0:68.3.0-3.el6_10
  • M
Information Exposure

*
  • H
Buffer Overflow

<0:68.3.0-3.el6_10
  • H
Use After Free

<0:68.3.0-3.el6_10
  • H
Use After Free

<0:68.3.0-3.el6_10
  • H
Improper Input Validation

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • L
Improper Neutralization of Special Elements

*
  • C
Use After Free

*
  • L
User Interface (UI) Misrepresentation of Critical Information

*
  • M
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

*
  • H
Information Exposure

*
  • M
Incorrect Default Permissions

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-bounds Read

*
  • M
Files or Directories Accessible to External Parties

*
  • M
Resource Exhaustion

*
  • H
Heap-based Buffer Overflow

<0:68.2.0-2.el6_10
  • H
Use After Free

<0:68.2.0-2.el6_10
  • H
Buffer Overflow

<0:68.2.0-2.el6_10
  • H
Buffer Overflow

<0:68.2.0-2.el6_10
  • H
Heap-based Buffer Overflow

<0:68.2.0-2.el6_10
  • H
Product UI does not Warn User of Unsafe Actions

<0:60.9.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:68.2.0-2.el6_10
  • H
Exposed Dangerous Method or Function

<0:68.2.0-2.el6_10
  • H
Cross-site Scripting (XSS)

<0:68.2.0-2.el6_10
  • H
Buffer Overflow

<0:68.2.0-2.el6_10
  • H
Use After Free

<0:60.9.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.9.0-1.el6_10
  • H
Cross-site Scripting (XSS)

<0:60.9.0-1.el6_10
  • H
Use After Free

<0:60.9.0-1.el6_10
  • H
Buffer Overflow

<0:60.9.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.9.0-1.el6_10
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:60.8.0-1.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.7.2-2.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.7.2-2.el6_10
  • H
Privilege Context Switching Error

<0:60.7.2-2.el6_10
  • H
Use After Free

<0:60.8.0-1.el6_10
  • H
Buffer Overflow

<0:60.8.0-1.el6_10
  • H
Cross-site Scripting (XSS)

<0:60.8.0-1.el6_10
  • H
Stack-based Buffer Overflow

<0:60.7.2-2.el6_10
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:60.8.0-1.el6_10
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.8.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.8.0-1.el6_10
  • H
Heap-based Buffer Overflow

<0:60.7.2-2.el6_10
  • H
Heap-based Buffer Overflow

<0:60.7.2-2.el6_10
  • H
Improper Neutralization of Special Elements

<0:60.8.0-1.el6_10
  • H
Resource Exhaustion

<0:60.7.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.7.0-1.el6_10
  • H
Unsynchronized Access to Shared Data in a Multithreaded Context

<0:60.7.0-1.el6_10
  • H
Buffer Overflow

<0:60.7.0-1.el6_10
  • H
Use After Free

<0:60.7.0-1.el6_10
  • H
Use After Free

<0:60.7.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.7.0-1.el6_10
  • H
Buffer Overflow

<0:60.7.0-1.el6_10
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.7.0-1.el6_10
  • H
Use After Free

<0:60.7.0-1.el6_10
  • H
Out-of-bounds Read

<0:60.7.0-1.el6_10
  • H
Information Exposure

<0:60.7.0-1.el6_10
  • H
Use After Free

<0:60.6.1-1.el6_10
  • H
Out-of-Bounds

<0:60.6.1-1.el6_10
  • H
Information Exposure

<0:60.6.1-1.el6_10
  • H
Integer Overflow or Wraparound

<0:60.6.1-1.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.6.1-1.el6_10
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:60.6.1-1.el6_10
  • H
Out-of-Bounds

<0:60.6.1-1.el6_10
  • H
Information Exposure

<0:60.6.1-1.el6_10
  • H
Use After Free

<0:60.6.1-1.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.6.1-1.el6_10
  • H
Use After Free

<0:60.6.1-1.el6_10
  • H
Buffer Overflow

<0:60.6.1-1.el6_10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.6.1-1.el6_10
  • L
Integer Overflow or Wraparound

*
  • H
Insufficient Verification of Data Authenticity

*
  • L
Link Following

*
  • M
Integer Overflow or Wraparound

*
  • L
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • L
Use After Free

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • L
Untrusted Search Path

*
  • M
Integer Overflow or Wraparound

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cryptographic Issues

*
  • M
Integer Overflow or Wraparound

*
  • M
Stack-based Buffer Overflow

*
  • M
CVE-2014-1586

*
  • M
CVE-2014-1585

*
  • L
Out-of-bounds Read

*
  • L
Out-of-Bounds

*
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:60.2.1-5.el6