Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2018-14767EPSS 24%

In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…

Fix: 5.0.7 / 5.1.4+
Fix from $2,300 2018-07-31
Debian Linux CRITICAL 9.8
CVE-2017-2640EPSS 6%

An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla…

Fix: 2.12.0+
Fix from $2,300 2018-07-27
Debian Linux CRITICAL 9.8
CVE-2018-1999010

FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can resu…

Fix: 3.4.3+
Fix from $2,300 2018-07-23
Debian Linux CRITICAL 9.8
CVE-2018-14349

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14350EPSS 5%

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi…

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14356

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14360

An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.

Fix: 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14361

An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.

Fix: 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-12584EPSS 25%

The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a deni…

Fix: after 1.10.2
Fix from $2,300 2018-07-16
Debian Linux CRITICAL 9.9
CVE-2018-12892

An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…

Fix: after 4.10.1
Fix from $2,300 2018-07-02
Devscripts CRITICAL 9.8
CVE-2018-13043

scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co…

Fix: after 2.18.3
Fix from $2,300 2018-07-01
Debian Linux CRITICAL 9.8
CVE-2018-13005

An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.

No fix yet
Fix from $2,300 2018-06-29
Debian Linux CRITICAL 9.8
CVE-2018-13006

An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

Patch available
Fix from $2,300 2018-06-29
Debian Linux CRITICAL 9.8
CVE-2017-7658EPSS 21%

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented w…

Fix: 9.3.24 / 9.4.11+
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2018-1000544

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …

Fix: after 1.2.1
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2018-1000550

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that…

Fix: 6.2.32+
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2018-1000517EPSS 33%

BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wge…

Fix: 1.29.0+
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2017-7657EPSS 16%

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transf…

Fix: 9.3.24 / 9.4.11+
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2018-12601

There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other im…

Patch available
Fix from $2,300 2018-06-20
Debian Linux CRITICAL 9.8
CVE-2018-5154

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitabl…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5155

A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable cras…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5159EPSS 14%

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5145

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that som…

Fix: 52.7.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5147

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vu…

Fix: 52.7.2 / 59.0.1+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5148

A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference count…

Fix: 52.7.3 / 59.0.2+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5150

Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and w…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5091

A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable c…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5095

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This result…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5096

A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerab…

Fix: 52.6.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5097EPSS 7%

A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content …

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11