Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2019-7314

liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to …

Fix: 0.95+
Fix from $2,300 2019-02-04
Debian Linux CRITICAL 9.8
CVE-2018-20748

LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.

Fix: 0.9.12 / 3.2.1.0+
Fix from $2,300 2019-01-30
Debian Linux CRITICAL 9.8
CVE-2019-6978

The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is un…

Patch available
Fix from $2,300 2019-01-28
Debian Linux CRITICAL 9.8
CVE-2018-20721

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address c…

Fix: 0.9.1+
Fix from $2,300 2019-01-16
Debian Linux CRITICAL 9.8
CVE-2019-6256

A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer cr…

No fix yet
Fix from $2,300 2019-01-14
Debian Linux CRITICAL 10.0
CVE-2018-14721EPSS 10%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14718EPSS 13%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14719EPSS 10%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt an…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14720EPSS 7%

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19360EPSS 10%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms c…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19361EPSS 10%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from po…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19362EPSS 10%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core cla…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19873

An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

Fix: 5.11.3+
Fix from $2,300 2018-12-26
Debian Linux CRITICAL 9.8
CVE-2018-20433

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

Patch available
Fix from $2,300 2018-12-24
Debian Linux CRITICAL 9.8
CVE-2018-1160EPSS 83%

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data.…

Fix: 1.2-7742-5 / 3.1.12+
Fix from $2,300 2018-12-20
Debian Linux CRITICAL 9.1
CVE-2018-19857

The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies…

No fix yet
Fix from $2,300 2018-12-05
Debian Linux CRITICAL 9.8
CVE-2018-19409EPSS 7%

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

Fix: 9.26+
Fix from $2,300 2018-11-21
Debian Linux CRITICAL 9.8
CVE-2018-19198

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function bec…

Fix: 0.9.0+
Fix from $2,300 2018-11-12
Debian Linux CRITICAL 9.8
CVE-2018-19199

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function becaus…

Fix: 0.9.0+
Fix from $2,300 2018-11-12
Debian Linux CRITICAL 9.8
CVE-2018-19115

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, becaus…

Fix: 2.0.7+
Fix from $2,300 2018-11-08
Debian Linux CRITICAL 9.8
CVE-2018-4013EPSS 10%

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specia…

No fix yet
Fix from $2,300 2018-10-19
Debian Linux CRITICAL 9.8
CVE-2018-5188

Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presum…

Fix: 52.9 / 60.1.0+
Fix from $2,300 2018-10-18
Debian Linux CRITICAL 9.8
CVE-2018-5187

Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Fix: 60.0 / 60.1.0+
Fix from $2,300 2018-10-18
Debian Linux CRITICAL 9.8
CVE-2018-17963

qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possib…

Fix: after 3.0.0
Fix from $2,300 2018-10-09
Debian Linux CRITICAL 9.8
CVE-2018-17141EPSS 5%

HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit en…

No fix yet
Fix from $2,300 2018-09-21
Debian Linux CRITICAL 9.8
CVE-2018-16947

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not…

Fix: 1.6.23 / 1.8.2+
Fix from $2,300 2018-09-12
Debian Linux CRITICAL 9.8
CVE-2018-16657

In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. T…

Fix: 5.0.7 / 5.1.4+
Fix from $2,300 2018-09-07
Debian Linux CRITICAL 9.8
CVE-2018-16402

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecif…

No fix yet
Fix from $2,300 2018-09-03
Debian Linux CRITICAL 9.8
CVE-2018-15494

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

Fix: 1.14+
Fix from $2,300 2018-08-18
Debian Linux CRITICAL 9.8
CVE-2015-9262EPSS 6%

_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a…

Fix: 1.1.15+
Fix from $2,300 2018-08-01