Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2013-2739

MiniDLNA has heap-based buffer overflow

Fix: 1.1.0+
Fix from $2,300 2019-11-01
Debian Linux CRITICAL 9.8
CVE-2013-1910

yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Tro…

Mitigation only
Fix from $2,300 2019-10-31
Overkill CRITICAL 9.8
CVE-2009-5041

overkill has buffer overflow via long player names that can corrupt data on the server machine

Fix: 0.16-14.1+
Fix from $2,300 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2009-5043

burn allows file names to escape via mishandled quotation marks

No fix yet
Fix from $2,300 2019-10-31
Debian Linux CRITICAL 9.1
CVE-2009-5042

python-docutils allows insecure usage of temporary files

Mitigation only
Fix from $2,300 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2019-18425

An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. Ther…

Fix: after 4.12.1
Fix from $2,300 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2010-0748

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr a…

Fix: 1.92+
Fix from $2,300 2019-10-30
Debian Linux CRITICAL 9.8
CVE-2019-17545

GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

Fix: after 3.0.1
Fix from $2,300 2019-10-14
Debian Linux CRITICAL 9.8
CVE-2019-17539

In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no va…

Fix: 3.4.7 / 4.0.5+
Fix from $2,300 2019-10-14
Debian Linux CRITICAL 9.8
CVE-2019-17531EPSS 5%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-12
Debian Linux CRITICAL 9.8
CVE-2019-17455

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations,…

Fix: after 1.5
Fix from $2,300 2019-10-10
Debian Linux CRITICAL 9.1
CVE-2019-17362

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 seque…

Fix: after 1.18.2
Fix from $2,300 2019-10-09
Debian Linux CRITICAL 9.8
CVE-2019-17041

An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages.…

Patch available
Fix from $2,300 2019-10-07
Debian Linux CRITICAL 9.8
CVE-2019-16942EPSS 6%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Debian Linux CRITICAL 9.8
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Debian Linux CRITICAL 9.8
CVE-2019-15941

OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat…

Fix: after 2.0.5
Fix from $2,300 2019-09-25
Debian Linux CRITICAL 9.8
CVE-2019-16378

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect …

Fix: after 1.3.2
Fix from $2,300 2019-09-17
Debian Linux CRITICAL 9.8
CVE-2019-15846EPSS 28%

Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

Fix: 4.92.2+
Fix from $2,300 2019-09-06
Debian Linux CRITICAL 9.8
CVE-2019-11500EPSS 63%

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs bec…

Fix: 0.5.7.2 / 2.2.36.4+
Fix from $2,300 2019-08-29
Debian Linux CRITICAL 9.8
CVE-2019-13273

In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET req…

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13451

In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13452

In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13455

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in ackno…

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13484

In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13485

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter …

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13486

In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-11187

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t…

Fix: after 2019-04-11
Fix from $2,300 2019-08-15
Debian Linux CRITICAL 9.8
CVE-2019-14379EPSS 8%

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transact…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $2,300 2019-07-29
Debian Linux CRITICAL 9.8
CVE-2019-13917EPSS 8%

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for item…

Fix: after 4.92
Fix from $2,300 2019-07-25
Debian Linux CRITICAL 9.8
CVE-2019-1010174

CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attac…

Fix: 2.3.4+
Fix from $2,300 2019-07-25