Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Bind HIGH 7.5
CVE-2018-5742

While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat ver…

Fix: after 9.9.4-72
Fix from $1,950 2019-10-30
Bind HIGH 7.5
CVE-2019-6476

A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than …

Fix: after 9.15.4
Fix from $1,950 2019-10-17
Kea MEDIUM 6.5
CVE-2019-6472

A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.…

Fix: after 1.5.0
Fix from $1,600 2019-10-16
Kea MEDIUM 6.5
CVE-2019-6473

An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Version…

Fix: after 1.5.0
Fix from $1,600 2019-10-16
Bind HIGH 7.5
CVE-2019-6469

An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response …

Mitigation only
Fix from $1,950 2019-10-09
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2019-6471

A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versi…

Fix: after 13.1.1
Fix from $1,600 2019-10-09
Bind HIGH 7.5
CVE-2019-6467EPSS 5%

A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect i…

Fix: after 9.13.7
Fix from $1,950 2019-10-09
Bind HIGH 7.5
CVE-2019-6468

In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. I…

Mitigation only
Fix from $1,950 2019-10-09
Debian Linux HIGH 7.5
CVE-2019-15892EPSS 6%

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to tr…

Fix: 6.0.4 / 6.2.1+
Fix from $1,950 2019-09-03
Binaryen MEDIUM 6.5
CVE-2019-15758

An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm…

Fix: 89+
Fix from $1,600 2019-08-29
Suricata HIGH 7.5
CVE-2019-10055

An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within …

No fix yet
Fix from $1,950 2019-08-28
Debian Linux MEDIUM 5.5
CVE-2019-13223

A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a cr…

Fix: after 2019-03-04
Fix from $1,600 2019-08-15
Yara MEDIUM 5.5
CVE-2019-5020

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a n…

No fix yet
Fix from $1,600 2019-07-31
Libopenmpt MEDIUM 6.5
CVE-2019-14382

DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

Fix: 0.4.2+
Fix from $1,600 2019-07-30
Libopenmpt MEDIUM 6.5
CVE-2019-14383

J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

Fix: 0.4.2+
Fix from $1,600 2019-07-30
Jsish HIGH 7.5
CVE-2019-1010173

Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c…

Patch available
Fix from $1,950 2019-07-23
Fedora MEDIUM 6.5
CVE-2019-13113

Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image fil…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Libreswan HIGH 7.5
CVE-2019-12312

In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IK…

Fix: 3.28+
Fix from $1,950 2019-05-24
Firefox CRITICAL 9.8
CVE-2019-9795

A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a pote…

Fix: 60.6 / 66.0+
Fix from $2,300 2019-04-26
Enterprise Linux Server Aus HIGH 7.5
CVE-2017-3139

A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly w…

Mitigation only
Fix from $1,950 2019-04-09
Wireshark HIGH 7.5
CVE-2019-10894EPSS 6%

In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by …

Fix: after 2.6.7
Fix from $1,950 2019-04-09
Fedora MEDIUM 6.5
CVE-2019-9211

There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that…

No fix yet
Fix from $1,600 2019-02-27
Bento4 MEDIUM 6.5
CVE-2019-7697

An issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Atom.cpp, leading to a denial of…

No fix yet
Fix from $1,600 2019-02-10
Binaryen MEDIUM 6.5
CVE-2019-7662

An assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This allows remote attackers to cau…

Fix: 65+
Fix from $1,600 2019-02-09
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5740EPSS 60%

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potenti…

Fix: 9.8.8 / 9.9.13+
Fix from $1,950 2019-01-16
Enterprise Linux Desktop MEDIUM 5.9
CVE-2017-3136EPSS 11%

A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could de…

Fix: after 9.10.4
Fix from $1,600 2019-01-16
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3137EPSS 9%

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a sit…

Mitigation only
Fix from $1,950 2019-01-16
Debian Linux MEDIUM 5.3
CVE-2017-3138EPSS 6%

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel…

Mitigation only
Fix from $1,600 2019-01-16
Bind HIGH 7.5
CVE-2018-5734EPSS 6%

While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has …

Mitigation only
Fix from $1,950 2019-01-16
Bind MEDIUM 5.3
CVE-2018-5736EPSS 18%

An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts sever…

Mitigation only
Fix from $1,600 2019-01-16