Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2017-1000421

Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution

Fix: after 1.89
Fix from $2,300 2018-01-02
Debian Linux CRITICAL 9.8
CVE-2014-4914

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…

Fix: 1.12.7+
Fix from $2,300 2017-12-29
Debian Linux CRITICAL 9.8
CVE-2017-17480EPSS 5%

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou…

Mitigation only
Fix from $2,300 2017-12-08
Debian Linux CRITICAL 9.8
CVE-2017-17458EPSS 6%

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a …

Fix: 4.4.1+
Fix from $2,300 2017-12-07
Debian Linux CRITICAL 9.8
CVE-2017-17434

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (i…

Fix: after 3.1.2
Fix from $2,300 2017-12-06
Most CRITICAL 9.8
CVE-2016-1253

The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote …

Fix: 5.0.0a-2.2 / 5.0.0a-2.3+
Fix from $2,300 2017-12-05
Debian Linux CRITICAL 9.8
CVE-2017-16943EPSS 44%

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of…

Patch available
Fix from $2,300 2017-11-25
Debian Linux CRITICAL 9.8
CVE-2017-16613EPSS 7%

An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …

Fix: after 2.15.1
Fix from $2,300 2017-11-21
Debian Linux CRITICAL 9.8
CVE-2017-16840

The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorre…

Patch available
Fix from $2,300 2017-11-21
Debian Linux CRITICAL 10.0
CVE-2017-16845

hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.

Fix: after 2.11.2
Fix from $2,300 2017-11-17
Debian Linux CRITICAL 9.8
CVE-2017-16872

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cse…

Fix: 2.7.1+
Fix from $2,300 2017-11-17
Debian Linux CRITICAL 9.1
CVE-2017-8807

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sen…

Fix: 4.1.9 / 5.2.1+
Fix from $2,300 2017-11-16
Debian Linux CRITICAL 9.8
CVE-2017-8809EPSS 6%

api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.

Fix: after 1.27.3
Fix from $2,300 2017-11-15
Debian Linux CRITICAL 9.1
CVE-2017-1000257EPSS 6%

An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl woul…

Fix: after 7.56.0
Fix from $2,300 2017-10-31
Debian Linux CRITICAL 9.6
CVE-2017-10285

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u1…

Patch available
Fix from $2,300 2017-10-19
Ftpsync CRITICAL 9.1
CVE-2017-8805

Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a…

Fix: after 20171016
Fix from $2,300 2017-10-17
Debian Linux CRITICAL 9.8
CVE-2017-0903EPSS 15%

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio…

Patch available
Fix from $2,300 2017-10-11
Debian Linux CRITICAL 9.8
CVE-2017-1000116

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

Fix: 4.3+
Fix from $2,300 2017-10-05
Debian Linux CRITICAL 9.8
CVE-2017-14632EPSS 6%

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…

Mitigation only
Fix from $2,300 2017-09-21
Debian Linux CRITICAL 9.8
CVE-2017-13687

The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13725

The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13024

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13028

The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13004

The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13020

The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12896

The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12899

The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12902

The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12987

The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.1
CVE-2017-14122

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.

Mitigation only
Fix from $2,300 2017-09-03