Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-7314 liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to … Debian Linux 0.95+ Fix from $2,3002019-02-04 CRITICAL 9.8 CVE-2018-20748 LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. Debian Linux 0.9.12 / 3.2.1.0+ Fix from $2,3002019-01-30 CRITICAL 9.8 CVE-2019-6978 The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is un… Debian Linux Patch available Fix from $2,3002019-01-28 CRITICAL 9.8 CVE-2018-20721 URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address c… Debian Linux 0.9.1+ Fix from $2,3002019-01-16 CRITICAL 9.8 CVE-2019-6256 A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer cr… Debian Linux No fix yet Fix from $2,3002019-01-14 CRITICAL 10.0 CVE-2018-14721EPSS 10% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure … Debian Linux 2.6.7.2 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14718EPSS 13% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class… Debian Linux 2.6.7.3 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14719EPSS 10% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt an… Debian Linux 2.6.7.3 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14720EPSS 7% FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci… Debian Linux 2.6.7.2 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19360EPSS 10% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms c… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19361EPSS 10% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from po… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19362EPSS 10% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core cla… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19873 An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. Debian Linux 5.11.3+ Fix from $2,3002018-12-26 CRITICAL 9.8 CVE-2018-20433 c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. Debian Linux Patch available Fix from $2,3002018-12-24 CRITICAL 9.8 CVE-2018-1160EPSS 83% Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data.… Debian Linux 1.2-7742-5 / 3.1.12+ Fix from $2,3002018-12-20 CRITICAL 9.1 CVE-2018-19857 The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies… Debian Linux No fix yet Fix from $2,3002018-12-05 CRITICAL 9.8 CVE-2018-19409EPSS 7% An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used. Debian Linux 9.26+ Fix from $2,3002018-11-21 CRITICAL 9.8 CVE-2018-19198 An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function bec… Debian Linux 0.9.0+ Fix from $2,3002018-11-12 CRITICAL 9.8 CVE-2018-19199 An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function becaus… Debian Linux 0.9.0+ Fix from $2,3002018-11-12 CRITICAL 9.8 CVE-2018-19115 keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, becaus… Debian Linux 2.0.7+ Fix from $2,3002018-11-08 CRITICAL 9.8 CVE-2018-4013EPSS 10% An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specia… Debian Linux No fix yet Fix from $2,3002018-10-19 CRITICAL 9.8 CVE-2018-5188 Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presum… Debian Linux 52.9 / 60.1.0+ Fix from $2,3002018-10-18 CRITICAL 9.8 CVE-2018-5187 Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough … Debian Linux 60.0 / 60.1.0+ Fix from $2,3002018-10-18 CRITICAL 9.8 CVE-2018-17963 qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possib… Debian Linux after 3.0.0 Fix from $2,3002018-10-09 CRITICAL 9.8 CVE-2018-17141EPSS 5% HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit en… Debian Linux No fix yet Fix from $2,3002018-09-21 CRITICAL 9.8 CVE-2018-16947 An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not… Debian Linux 1.6.23 / 1.8.2+ Fix from $2,3002018-09-12 CRITICAL 9.8 CVE-2018-16657 In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. T… Debian Linux 5.0.7 / 5.1.4+ Fix from $2,3002018-09-07 CRITICAL 9.8 CVE-2018-16402 libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecif… Debian Linux No fix yet Fix from $2,3002018-09-03 CRITICAL 9.8 CVE-2018-15494 In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. Debian Linux 1.14+ Fix from $2,3002018-08-18 CRITICAL 9.8 CVE-2015-9262EPSS 6% _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a… Debian Linux 1.1.15+ Fix from $2,3002018-08-01