Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-14767EPSS 24% In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an… Debian Linux 5.0.7 / 5.1.4+ Fix from $2,3002018-07-31 CRITICAL 9.8 CVE-2017-2640EPSS 6% An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla… Debian Linux 2.12.0+ Fix from $2,3002018-07-27 CRITICAL 9.8 CVE-2018-1999010 FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can resu… Debian Linux 3.4.3+ Fix from $2,3002018-07-23 CRITICAL 9.8 CVE-2018-14349 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message. Debian Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14350EPSS 5% An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi… Debian Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14356 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID. Debian Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14360 An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage. Debian Linux 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14361 An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data. Debian Linux 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-12584EPSS 25% The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a deni… Debian Linux after 1.10.2 Fix from $2,3002018-07-16 CRITICAL 9.9 CVE-2018-12892 An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl… Debian Linux after 4.10.1 Fix from $2,3002018-07-02 CRITICAL 9.8 CVE-2018-13043 scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co… Devscripts after 2.18.3 Fix from $2,3002018-07-01 CRITICAL 9.8 CVE-2018-13005 An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. Debian Linux No fix yet Fix from $2,3002018-06-29 CRITICAL 9.8 CVE-2018-13006 An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. Debian Linux Patch available Fix from $2,3002018-06-29 CRITICAL 9.8 CVE-2017-7658EPSS 21% In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented w… Debian Linux 9.3.24 / 9.4.11+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-1000544 rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary … Debian Linux after 1.2.1 Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-1000550 The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that… Debian Linux 6.2.32+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-1000517EPSS 33% BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wge… Debian Linux 1.29.0+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2017-7657EPSS 16% In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transf… Debian Linux 9.3.24 / 9.4.11+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-12601 There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other im… Debian Linux Patch available Fix from $2,3002018-06-20 CRITICAL 9.8 CVE-2018-5154 A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitabl… Debian Linux 52.8.0 / 60.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5155 A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable cras… Debian Linux 52.8.0 / 60.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5159EPSS 14% An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of… Debian Linux 52.8.0 / 60.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5145 Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that som… Debian Linux 52.7.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5147 The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vu… Debian Linux 52.7.2 / 59.0.1+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5148 A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference count… Debian Linux 52.7.3 / 59.0.2+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5150 Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and w… Debian Linux 52.8.0 / 60.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5091 A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable c… Debian Linux 52.6.0 / 58.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5095 An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This result… Debian Linux 52.6.0 / 58.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5096 A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerab… Debian Linux 52.6.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5097EPSS 7% A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content … Debian Linux 52.6.0 / 58.0+ Fix from $2,3002018-06-11