Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2020-15227EPSS 34%

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…

Fix: 2.0.19 / 2.1.13+
Fix from $2,300 2020-10-01
Debian Linux CRITICAL 9.8
CVE-2020-24660

An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Host…

Fix: after 2.0.8
Fix from $2,300 2020-09-14
Debian Linux CRITICAL 9.8
CVE-2020-24361

SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.

Fix: 1.4.2+
Fix from $2,300 2020-08-16
Debian Linux CRITICAL 9.8
CVE-2020-17446

asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server r…

Fix: 0.21.0+
Fix from $2,300 2020-08-12
Debian Linux CRITICAL 9.8
CVE-2020-17368

Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.

Fix: after 0.9.62
Fix from $2,300 2020-08-11
Debian Linux CRITICAL 9.8
CVE-2020-15866

mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can b…

Fix: after 2.1.1
Fix from $2,300 2020-07-21
Debian Linux CRITICAL 9.1
CVE-2020-15472

In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated …

Fix: after 3.2
Fix from $2,300 2020-07-01
Debian Linux CRITICAL 9.1
CVE-2020-13112

An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…

Fix: 0.6.22+
Fix from $2,300 2020-05-21
Debian Linux CRITICAL 9.8
CVE-2020-11651 KEVEPSS 97%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate…

Fix: 2019.2.4 / 3000.2+
Fix from $2,300 2020-04-30
Debian Linux CRITICAL 9.8
CVE-2020-12278EPSS 5%

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate …

Fix: 0.28.4+
Fix from $2,300 2020-04-27
Debian Linux CRITICAL 9.8
CVE-2020-12279EPSS 5%

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short …

Fix: 0.28.4+
Fix from $2,300 2020-04-27
Debian Linux CRITICAL 9.8
CVE-2020-12268

jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

Fix: 0.18+
Fix from $2,300 2020-04-27
Debian Linux CRITICAL 9.8
CVE-2020-11945EPSS 27%

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that ar…

Fix: 4.11 / 5.0.2+
Fix from $2,300 2020-04-23
Debian Linux CRITICAL 9.8
CVE-2019-12519EPSS 7%

An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function …

Fix: after 5.0.1
Fix from $2,300 2020-04-15
Debian Linux CRITICAL 9.8
CVE-2019-12524

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid…

Fix: after 4.7
Fix from $2,300 2020-04-15
Debian Linux CRITICAL 9.8
CVE-2020-11729

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity…

Fix: after 0.60
Fix from $2,300 2020-04-15
Debian Linux CRITICAL 9.8
CVE-2020-10595

pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library…

Fix: 4.9+
Fix from $2,300 2020-03-31
Debian Linux CRITICAL 9.8
CVE-2020-6072

An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels …

No fix yet
Fix from $2,300 2020-03-24
Debian Linux CRITICAL 9.8
CVE-2020-10938EPSS 5%

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

Fix: 1.3.35+
Fix from $2,300 2020-03-24
Debian Linux CRITICAL 9.8
CVE-2020-9760

An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buff…

Fix: 2.7.1+
Fix from $2,300 2020-03-23
Debian Linux CRITICAL 9.8
CVE-2020-10232

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaf…

Fix: after 4.8.0
Fix from $2,300 2020-03-09
Debian Linux CRITICAL 9.8
CVE-2020-9355

danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.

Fix: 1.2.11+
Fix from $2,300 2020-02-23
Debian Linux CRITICAL 9.8
CVE-2020-8840EPSS 27%

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC…

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-02-10
Debian Linux CRITICAL 9.8
CVE-2020-8597EPSS 20%

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

Fix: 03.04.10+
Fix from $2,300 2020-02-03
Debian Linux CRITICAL 9.1
CVE-2019-20444EPSS 9%

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incor…

Fix: 4.1.44+
Fix from $2,300 2020-01-29
Debian Linux CRITICAL 9.1
CVE-2019-20445EPSS 13%

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-En…

Fix: 4.1.44+
Fix from $2,300 2020-01-29
Debian Linux CRITICAL 9.8
CVE-2020-7247 KEVEPSS 99%

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as…

Patch available
Fix from $2,300 2020-01-29
Debian Linux CRITICAL 9.8
CVE-2015-8011EPSS 5%

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (da…

Fix: 0.8.0+
Fix from $2,300 2020-01-28
Debian Linux CRITICAL 9.8
CVE-2020-8086

The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f…

Fix: after 2020-01-27
Fix from $2,300 2020-01-28
Debian Linux CRITICAL 9.8
CVE-2014-4172EPSS 6%

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.…

Fix: 1.0.2 / 1.3.3+
Fix from $2,300 2020-01-24