Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2021-31872

An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overf…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-31873

An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer over…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-25216EPSS 82%

In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition,…

Fix: 1.0.1.1 / 9.11.31+
Fix from $2,300 2021-04-29
Debian Linux CRITICAL 9.8
CVE-2019-25032

Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability.…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25033

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerabil…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25034

Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25035

Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25038

Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability.…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25039

Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Alt…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25042

Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Altho…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2021-30164

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.

Fix: 4.0.8 / 4.1.2+
Fix from $2,300 2021-04-06
Debian Linux CRITICAL 9.8
CVE-2021-20308

Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-…

Fix: after 1.9.11
Fix from $2,300 2021-04-05
Debian Linux CRITICAL 9.8
CVE-2021-1871 KEVEPSS 7%

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update…

Fix: 10.15.7 / 11.2+
Fix from $2,300 2021-04-02
Debian Linux CRITICAL 9.8
CVE-2020-35636

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::re…

No fix yet
Fix from $2,300 2021-03-04
Debian Linux CRITICAL 9.8
CVE-2021-26120EPSS 82%

Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

Fix: 3.1.39+
Fix from $2,300 2021-02-22
Debian Linux CRITICAL 9.8
CVE-2021-27135EPSS 8%

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combi…

Fix: 366+
Fix from $2,300 2021-02-10
Debian Linux CRITICAL 9.8
CVE-2020-36244

The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute a…

Fix: 2.18.6+
Fix from $2,300 2021-02-10
Debian Linux CRITICAL 9.8
CVE-2021-26937EPSS 9%

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly …

Fix: after 4.8.0
Fix from $2,300 2021-02-09
Debian Linux CRITICAL 9.8
CVE-2020-12658

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment s…

Fix: 0.8.3+
Fix from $2,300 2020-12-31
Debian Linux CRITICAL 9.8
CVE-2020-35605

The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing sp…

Fix: 0.19.3+
Fix from $2,300 2020-12-21
Debian Linux CRITICAL 9.8
CVE-2020-7788

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pol…

Fix: 1.3.6+
Fix from $2,300 2020-12-11
Debian Linux CRITICAL 9.8
CVE-2020-29600

In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/…

Fix: after 7.7
Fix from $2,300 2020-12-07
Debian Linux CRITICAL 9.8
CVE-2020-28926EPSS 13%

ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTT…

Fix: 1.3.0+
Fix from $2,300 2020-11-30
Debian Linux CRITICAL 9.8
CVE-2020-27745

Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.

Fix: 19.05.8 / 20.02.6+
Fix from $2,300 2020-11-27
Debian Linux CRITICAL 9.8
CVE-2020-28984

prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils…

Fix: 3.2.8+
Fix from $2,300 2020-11-23
Debian Linux CRITICAL 9.8
CVE-2019-20933EPSS 31%

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may ha…

Fix: 1.7.6+
Fix from $2,300 2020-11-19
Debian Linux CRITICAL 9.8
CVE-2020-25074EPSS 7%

The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload …

Fix: after 1.9.10
Fix from $2,300 2020-11-10
Debian Linux CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2020-25592EPSS 58%

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2020-11800EPSS 9%

Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

Fix: 3.0.31+
Fix from $2,300 2020-10-07