Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2018-10191

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of de…

Fix: after 1.4.0
Fix from $2,300 2018-04-17
Debian Linux CRITICAL 9.8
CVE-2018-6797EPSS 6%

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes w…

Fix: after 5.26
Fix from $2,300 2018-04-17
Debian Linux CRITICAL 9.8
CVE-2018-6913EPSS 10%

Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item c…

Fix: 5.26.2+
Fix from $2,300 2018-04-17
Debian Linux CRITICAL 9.8
CVE-2017-0359

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

Fix: 77+
Fix from $2,300 2018-04-13
Debian Linux CRITICAL 9.8
CVE-2017-0372EPSS 10%

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Fix: after 1.23.15
Fix from $2,300 2018-04-13
Debian Linux CRITICAL 9.8
CVE-2017-0356

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker …

Fix: 3.20170111+
Fix from $2,300 2018-04-13
Debian Linux CRITICAL 9.8
CVE-2017-0357

A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

Fix: 2.1.1+
Fix from $2,300 2018-04-13
Debian Linux CRITICAL 9.8
CVE-2018-1000140EPSS 9%

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result …

Patch available
Fix from $2,300 2018-03-23
Debian Linux CRITICAL 9.8
CVE-2018-8828EPSS 28%

A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message wit…

Fix: 4.4.7 / 5.0.6+
Fix from $2,300 2018-03-20
Debian Linux CRITICAL 9.8
CVE-2018-7033

SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.

Fix: 17.02.10.0 / 17.11.5.0+
Fix from $2,300 2018-03-15
Debian Linux CRITICAL 9.8
CVE-2018-1000120EPSS 11%

A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or …

Fix: 7.2+
Fix from $2,300 2018-03-14
Debian Linux CRITICAL 9.1
CVE-2018-1000122EPSS 8%

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of serv…

Fix: 7.2+
Fix from $2,300 2018-03-14
Debian Linux CRITICAL 9.1
CVE-2018-1000132

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data…

Fix: 4.5.1+
Fix from $2,300 2018-03-14
Debian Linux CRITICAL 9.8
CVE-2018-1000076

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $2,300 2018-03-13
Debian Linux CRITICAL 9.8
CVE-2018-1000116EPSS 6%

NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.

No fix yet
Fix from $2,300 2018-03-07
Debian Linux CRITICAL 9.1
CVE-2018-7556

LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installatio…

Fix: 2.6.7 / 2.73.1+
Fix from $2,300 2018-02-28
Debian Linux CRITICAL 9.8
CVE-2018-7551

There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial o…

No fix yet
Fix from $2,300 2018-02-28
Debian Linux CRITICAL 9.8
CVE-2018-7552

There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead t…

No fix yet
Fix from $2,300 2018-02-28
Debian Linux CRITICAL 9.8
CVE-2018-7553

There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service o…

No fix yet
Fix from $2,300 2018-02-28
Debian Linux CRITICAL 9.8
CVE-2018-7554

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of se…

No fix yet
Fix from $2,300 2018-02-28
Debian Linux CRITICAL 9.8
CVE-2018-7489EPSS 18%

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an in…

Fix: 2.7.9.3 / 2.8.11.1+
Fix from $2,300 2018-02-26
Debian Linux CRITICAL 9.8
CVE-2018-7440

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo…

Fix: after 1.75.3
Fix from $2,300 2018-02-23
Debian Linux CRITICAL 9.8
CVE-2017-7375

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…

Fix: after 2.9.4
Fix from $2,300 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2017-7376EPSS 23%

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

Fix: 2.9.5+
Fix from $2,300 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2018-7225EPSS 5%

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to a…

No fix yet
Fix from $2,300 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2018-5379EPSS 37%

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a…

Fix: after 1.2.2
Fix from $2,300 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2018-7186

Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a…

Fix: 1.75.3+
Fix from $2,300 2018-02-16
Debian Linux CRITICAL 9.8
CVE-2018-7053

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected orde…

Fix: 1.0.7+
Fix from $2,300 2018-02-15
Debian Linux CRITICAL 9.8
CVE-2017-18187

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity…

Fix: 2.7.0+
Fix from $2,300 2018-02-14
Debian Linux CRITICAL 9.8
CVE-2018-0487

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ov…

Fix: 1.3.22 / 2.1.10+
Fix from $2,300 2018-02-13