Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2018-0488

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute a…

Fix: 1.3.22 / 2.1.10+
Fix from $2,300 2018-02-13
Debian Linux CRITICAL 9.8
CVE-2018-6871EPSS 18%

LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.…

Patch available
Fix from $2,300 2018-02-09
Debian Linux CRITICAL 9.8
CVE-2018-6789 KEVEPSS 82%

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may h…

Fix: 4.90.1+
Fix from $2,300 2018-02-08
Debian Linux CRITICAL 9.8
CVE-2017-15095EPSS 8%

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo…

Fix: 2.6.7.2 / 2.7.9.2+
Fix from $2,300 2018-02-06
Debian Linux CRITICAL 9.8
CVE-2017-7525EPSS 38%

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user …

Fix: 2.6.7.1 / 2.7.9.1+
Fix from $2,300 2018-02-06
Debian Linux CRITICAL 9.1
CVE-2018-6596

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al…

Fix: 1.2.1+
Fix from $2,300 2018-02-03
Debian Linux CRITICAL 9.8
CVE-2018-6521

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. T…

Fix: 1.15.2+
Fix from $2,300 2018-02-02
Debian Linux CRITICAL 9.8
CVE-2016-10711

Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.

Fix: after 2.7
Fix from $2,300 2018-01-29
Debian Linux CRITICAL 9.8
CVE-2017-12377EPSS 10%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $2,300 2018-01-26
Debian Linux CRITICAL 9.8
CVE-2017-12379EPSS 11%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $2,300 2018-01-26
Debian Linux CRITICAL 9.1
CVE-2018-1000005

libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pu…

Fix: after 7.57.0
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12176

xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server t…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12177

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to cr…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12178

xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash o…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12179

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X s…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12180

xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or pos…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12181

xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possib…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12182

xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possib…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12183

xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly ex…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12184

xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly …

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12185

xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or p…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12186

xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibl…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12187

xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly ex…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.6
CVE-2018-5704

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attacker…

Patch available
Fix from $2,300 2018-01-16
Debian Linux CRITICAL 9.8
CVE-2017-17485EPSS 50%

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…

Fix: 2.6.7.3 / 2.7.9.2+
Fix from $2,300 2018-01-10
Debian Linux CRITICAL 9.8
CVE-2015-2320

The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

Fix: 3.12.1+
Fix from $2,300 2018-01-08
Debian Linux CRITICAL 9.8
CVE-2018-5206

When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.

Fix: 1.0.6+
Fix from $2,300 2018-01-06
Debian Linux CRITICAL 9.8
CVE-2018-5208

In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.

Fix: 1.0.6+
Fix from $2,300 2018-01-06
Debian Linux CRITICAL 9.8
CVE-2017-1000487EPSS 6%

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

Fix: 3.0.16+
Fix from $2,300 2018-01-03
Debian Linux CRITICAL 9.8
CVE-2017-1000501

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthen…

Fix: after 7.6.0
Fix from $2,300 2018-01-03