Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-14767EPSS 24%
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…
Debian Linux
5.0.7 / 5.1.4+
CRITICAL 9.8
CVE-2017-2640EPSS 6%
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla…
Debian Linux
2.12.0+
CRITICAL 9.8
CVE-2018-1999010
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can resu…
Debian Linux
3.4.3+
CRITICAL 9.8
CVE-2018-14349
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.
Debian Linux
1.10.1 / 20180716+
CRITICAL 9.8
CVE-2018-14350EPSS 5%
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi…
Debian Linux
1.10.1 / 20180716+
CRITICAL 9.8
CVE-2018-14356
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
Debian Linux
1.10.1 / 20180716+
CRITICAL 9.8
CVE-2018-14360
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
Debian Linux
20180716+
CRITICAL 9.8
CVE-2018-14361
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
Debian Linux
20180716+
CRITICAL 9.8
CVE-2018-12584EPSS 25%
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a deni…
Debian Linux
after 1.10.2
CRITICAL 9.9
CVE-2018-12892
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…
Debian Linux
after 4.10.1
CRITICAL 9.8
CVE-2018-13043
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co…
Devscripts
after 2.18.3
CRITICAL 9.8
CVE-2018-13005
An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2018-13006
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.
Debian Linux
Patch available
CRITICAL 9.8
CVE-2017-7658EPSS 21%
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented w…
Debian Linux
9.3.24 / 9.4.11+
CRITICAL 9.8
CVE-2018-1000544
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …
Debian Linux
after 1.2.1
CRITICAL 9.8
CVE-2018-1000550
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that…
Debian Linux
6.2.32+
CRITICAL 9.8
CVE-2018-1000517EPSS 33%
BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wge…
Debian Linux
1.29.0+
CRITICAL 9.8
CVE-2017-7657EPSS 16%
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transf…
Debian Linux
9.3.24 / 9.4.11+
CRITICAL 9.8
CVE-2018-12601
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other im…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2018-5154
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitabl…
Debian Linux
52.8.0 / 60.0+
CRITICAL 9.8
CVE-2018-5155
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable cras…
Debian Linux
52.8.0 / 60.0+
CRITICAL 9.8
CVE-2018-5159EPSS 14%
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of…
Debian Linux
52.8.0 / 60.0+
CRITICAL 9.8
CVE-2018-5145
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that som…
Debian Linux
52.7.0+
CRITICAL 9.8
CVE-2018-5147
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vu…
Debian Linux
52.7.2 / 59.0.1+
CRITICAL 9.8
CVE-2018-5148
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference count…
Debian Linux
52.7.3 / 59.0.2+
CRITICAL 9.8
CVE-2018-5150
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and w…
Debian Linux
52.8.0 / 60.0+
CRITICAL 9.8
CVE-2018-5091
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable c…
Debian Linux
52.6.0 / 58.0+
CRITICAL 9.8
CVE-2018-5095
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This result…
Debian Linux
52.6.0 / 58.0+
CRITICAL 9.8
CVE-2018-5096
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerab…
Debian Linux
52.6.0+
CRITICAL 9.8
CVE-2018-5097EPSS 7%
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content …
Debian Linux
52.6.0 / 58.0+