Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
HIGH 7.5 CVE-2018-5742 While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat ver… Bind after 9.9.4-72 Fix from $1,9502019-10-30 HIGH 7.5 CVE-2019-6476 A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than … Bind after 9.15.4 Fix from $1,9502019-10-17 MEDIUM 6.5 CVE-2019-6472 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.… Kea after 1.5.0 Fix from $1,6002019-10-16 MEDIUM 6.5 CVE-2019-6473 An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Version… Kea after 1.5.0 Fix from $1,6002019-10-16 HIGH 7.5 CVE-2019-6469 An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response … Bind Mitigation only Fix from $1,9502019-10-09 MEDIUM 5.9 CVE-2019-6471 A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versi… Big Ip Local Traffic Manager after 13.1.1 Fix from $1,6002019-10-09 HIGH 7.5 CVE-2019-6467EPSS 5% A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect i… Bind after 9.13.7 Fix from $1,9502019-10-09 HIGH 7.5 CVE-2019-6468 In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. I… Bind Mitigation only Fix from $1,9502019-10-09 HIGH 7.5 CVE-2019-15892EPSS 6% An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to tr… Debian Linux 6.0.4 / 6.2.1+ Fix from $1,9502019-09-03 MEDIUM 6.5 CVE-2019-15758 An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm… Binaryen 89+ Fix from $1,6002019-08-29 HIGH 7.5 CVE-2019-10055 An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within … Suricata No fix yet Fix from $1,9502019-08-28 MEDIUM 5.5 CVE-2019-13223 A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a cr… Debian Linux after 2019-03-04 Fix from $1,6002019-08-15 MEDIUM 5.5 CVE-2019-5020 An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a n… Yara No fix yet Fix from $1,6002019-07-31 MEDIUM 6.5 CVE-2019-14382 DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. Libopenmpt 0.4.2+ Fix from $1,6002019-07-30 MEDIUM 6.5 CVE-2019-14383 J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. Libopenmpt 0.4.2+ Fix from $1,6002019-07-30 HIGH 7.5 CVE-2019-1010173 Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c… Jsish Patch available Fix from $1,9502019-07-23 MEDIUM 6.5 CVE-2019-13113 Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image fil… Fedora after 0.27.1 Fix from $1,6002019-06-30 HIGH 7.5 CVE-2019-12312 In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IK… Libreswan 3.28+ Fix from $1,9502019-05-24 CRITICAL 9.8 CVE-2019-9795 A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a pote… Firefox 60.6 / 66.0+ Fix from $2,3002019-04-26 HIGH 7.5 CVE-2017-3139 A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly w… Enterprise Linux Server Aus Mitigation only Fix from $1,9502019-04-09 HIGH 7.5 CVE-2019-10894EPSS 6% In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by … Wireshark after 2.6.7 Fix from $1,9502019-04-09 MEDIUM 6.5 CVE-2019-9211 There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that… Fedora No fix yet Fix from $1,6002019-02-27 MEDIUM 6.5 CVE-2019-7697 An issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Atom.cpp, leading to a denial of… Bento4 No fix yet Fix from $1,6002019-02-10 MEDIUM 6.5 CVE-2019-7662 An assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This allows remote attackers to cau… Binaryen 65+ Fix from $1,6002019-02-09 HIGH 7.5 CVE-2018-5740EPSS 60% "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potenti… Enterprise Linux Desktop 9.8.8 / 9.9.13+ Fix from $1,9502019-01-16 MEDIUM 5.9 CVE-2017-3136EPSS 11% A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could de… Enterprise Linux Desktop after 9.10.4 Fix from $1,6002019-01-16 HIGH 7.5 CVE-2017-3137EPSS 9% Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a sit… Enterprise Linux Desktop Mitigation only Fix from $1,9502019-01-16 MEDIUM 5.3 CVE-2017-3138EPSS 6% named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel… Debian Linux Mitigation only Fix from $1,6002019-01-16 HIGH 7.5 CVE-2018-5734EPSS 6% While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has … Bind Mitigation only Fix from $1,9502019-01-16 MEDIUM 5.3 CVE-2018-5736EPSS 18% An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts sever… Bind Mitigation only Fix from $1,6002019-01-16