Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2019-13962

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not pr…

Fix: after 3.0.7
Fix from $2,300 2019-07-18
Debian Linux CRITICAL 9.8
CVE-2019-12525EPSS 24%

An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the heade…

Fix: after 4.7
Fix from $2,300 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-12838

SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.

Fix: after 18.08.7
Fix from $2,300 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-13132EPSS 42%

In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, runni…

Fix: 4.0.9 / 4.1.7+
Fix from $2,300 2019-07-10
Debian Linux CRITICAL 9.8
CVE-2019-12468

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow…

Fix: after 1.32.1
Fix from $2,300 2019-07-10
Debian Linux CRITICAL 9.8
CVE-2019-7165

A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2019-07-03
Debian Linux CRITICAL 9.8
CVE-2019-12594EPSS 6%

DOSBox 0.74-2 has Incorrect Access Control.

No fix yet
Fix from $2,300 2019-07-02
Debian Linux CRITICAL 9.8
CVE-2019-12900EPSS 8%

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

Fix: 3.7.13 / 3.8.13+
Fix from $2,300 2019-06-19
Debian Linux CRITICAL 9.8
CVE-2019-12450

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progre…

Fix: after 2.61.1
Fix from $2,300 2019-05-29
Debian Linux CRITICAL 9.8
CVE-2019-12046

LemonLDAP::NG -2.0.3 has Incorrect Access Control.

No fix yet
Fix from $2,300 2019-05-22
Debian Linux CRITICAL 9.8
CVE-2019-11766

dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.

Fix: 6.11.7 / 7.2.2+
Fix from $2,300 2019-05-05
Debian Linux CRITICAL 9.8
CVE-2019-11627

gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.

Fix: 2.10+
Fix from $2,300 2019-04-30
Debian Linux CRITICAL 9.1
CVE-2019-11006

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attac…

Fix: after 1.3.31
Fix from $2,300 2019-04-08
Debian Linux CRITICAL 9.1
CVE-2019-3860

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compr…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
Debian Linux CRITICAL 9.1
CVE-2019-3861

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length a…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
Debian Linux CRITICAL 9.8
CVE-2018-20177EPSS 8%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() a…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2018-20180EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_proces…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2018-20181EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2018-20182EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2019-9215

In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.

Fix: 2019.02.27+
Fix from $2,300 2019-02-28
Debian Linux CRITICAL 9.8
CVE-2019-7164

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Fix: after 1.2.17
Fix from $2,300 2019-02-20
Debian Linux CRITICAL 9.8
CVE-2019-7653

The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowi…

No fix yet
Fix from $2,300 2019-02-09
Debian Linux CRITICAL 9.8
CVE-2019-3463

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to …

Mitigation only
Fix from $2,300 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2019-3464

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restri…

Mitigation only
Fix from $2,300 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2018-8793EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8794EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() an…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8795EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_update…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8797EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8800EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-4056

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a…

Fix: 4.5.0.9+
Fix from $2,300 2019-02-05