Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2019-17361EPSS 15%

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticat…

Fix: after 2019.2.0
Fix from $2,300 2020-01-17
Debian Linux CRITICAL 9.1
CVE-2019-20367

nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

Fix: 0.10.0+
Fix from $2,300 2020-01-08
Debian Linux CRITICAL 9.1
CVE-2019-18792

An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet…

Fix: 4.1.6+
Fix from $2,300 2020-01-06
Debian Linux CRITICAL 9.8
CVE-2019-20330EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-01-03
Debian Linux CRITICAL 9.8
CVE-2019-19950

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.8
CVE-2019-19951

In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.1
CVE-2019-19949

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_pr…

Fix: 6.9.10-43 / 7.0.8-43+
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.1
CVE-2019-19953

In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.8
CVE-2012-6094

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

Fix: 1.5.4-1.1+
Fix from $2,300 2019-12-20
Debian Linux CRITICAL 9.8
CVE-2014-8650

python-requests-Kerberos through 0.5 does not handle mutual authentication

Fix: after 0.5
Fix from $2,300 2019-12-15
Debian Linux CRITICAL 9.3
CVE-2019-18345

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied…

Fix: after 1.1.8
Fix from $2,300 2019-12-12
Debian Linux CRITICAL 9.8
CVE-2019-19725

sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

Fix: after 12.2.0
Fix from $2,300 2019-12-11
Debian Linux CRITICAL 9.8
CVE-2012-1577

lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.

Mitigation only
Fix from $2,300 2019-12-10
Debian Linux CRITICAL 9.8
CVE-2019-19617

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.ph…

Fix: 4.9.2+
Fix from $2,300 2019-12-06
Debian Linux CRITICAL 9.8
CVE-2013-2745

An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

Fix: 1.1.0+
Fix from $2,300 2019-12-04
Debian Linux CRITICAL 9.8
CVE-2011-2523EPSS 96%

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

No fix yet
Fix from $2,300 2019-11-27
Debian Linux CRITICAL 9.8
CVE-2011-4120

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured…

Fix: 2.10+
Fix from $2,300 2019-11-26
Debian Linux CRITICAL 9.8
CVE-2014-6310

Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.

Patch available
Fix from $2,300 2019-11-22
Debian Linux CRITICAL 9.8
CVE-2014-6311

generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.

Fix: after 6.2.6
Fix from $2,300 2019-11-22
Debian Linux CRITICAL 9.8
CVE-2011-1028

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_s…

Fix: 3.0.7+
Fix from $2,300 2019-11-20
Debian Linux CRITICAL 9.8
CVE-2019-19012EPSS 11%

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offse…

Fix: after 6.9.3
Fix from $2,300 2019-11-17
Debian Linux CRITICAL 9.8
CVE-2011-0703

In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 ses…

Fix: 0.0.3+
Fix from $2,300 2019-11-15
Debian Linux CRITICAL 9.8
CVE-2013-7087

ClamAV before 0.97.7 has WWPack corrupt heap memory

Fix: 0.97.7+
Fix from $2,300 2019-11-15
Debian Linux CRITICAL 9.8
CVE-2013-7088

ClamAV before 0.97.7 has buffer overflow in the libclamav component

Fix: 0.97.7+
Fix from $2,300 2019-11-15
Debian Linux CRITICAL 9.8
CVE-2011-1930EPSS 21%

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker …

Fix: 1.5.25+
Fix from $2,300 2019-11-14
Debian Linux CRITICAL 9.8
CVE-2010-4533

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed proto…

Fix: 6.3.4+
Fix from $2,300 2019-11-13
Debian Linux CRITICAL 9.8
CVE-2010-3438

libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing…

Fix: 6.32+
Fix from $2,300 2019-11-12
Debian Linux CRITICAL 9.8
CVE-2008-7291

gri before 2.12.18 generates temporary files in an insecure way.

Fix: 2.12.18+
Fix from $2,300 2019-11-08
Debian Linux CRITICAL 9.8
CVE-2007-6745

clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

Mitigation only
Fix from $2,300 2019-11-07
Debian Linux CRITICAL 9.8
CVE-2007-0899

There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

Fix: 0.100.0+
Fix from $2,300 2019-11-06