Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-0488 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute a… Debian Linux 1.3.22 / 2.1.10+ Fix from $2,3002018-02-13 CRITICAL 9.8 CVE-2018-6871EPSS 18% LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.… Debian Linux Patch available Fix from $2,3002018-02-09 CRITICAL 9.8 CVE-2018-6789 KEVEPSS 82% An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may h… Debian Linux 4.90.1+ Fix from $2,3002018-02-08 CRITICAL 9.8 CVE-2017-15095EPSS 8% A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo… Debian Linux 2.6.7.2 / 2.7.9.2+ Fix from $2,3002018-02-06 CRITICAL 9.8 CVE-2017-7525EPSS 38% A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user … Debian Linux 2.6.7.1 / 2.7.9.1+ Fix from $2,3002018-02-06 CRITICAL 9.1 CVE-2018-6596 webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al… Debian Linux 1.2.1+ Fix from $2,3002018-02-03 CRITICAL 9.8 CVE-2018-6521 The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. T… Debian Linux 1.15.2+ Fix from $2,3002018-02-02 CRITICAL 9.8 CVE-2016-10711 Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751. Debian Linux after 2.7 Fix from $2,3002018-01-29 CRITICAL 9.8 CVE-2017-12377EPSS 10% ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of… Debian Linux after 0.99.2 Fix from $2,3002018-01-26 CRITICAL 9.8 CVE-2017-12379EPSS 11% ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of… Debian Linux after 0.99.2 Fix from $2,3002018-01-26 CRITICAL 9.1 CVE-2018-1000005 libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pu… Debian Linux after 7.57.0 Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12176 xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server t… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12177 xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to cr… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12178 xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash o… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12179 xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X s… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12180 xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or pos… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12181 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possib… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12182 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possib… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12183 xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly ex… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12184 xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly … Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12185 xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or p… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12186 xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibl… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12187 xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly ex… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.6 CVE-2018-5704 Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attacker… Debian Linux Patch available Fix from $2,3002018-01-16 CRITICAL 9.8 CVE-2017-17485EPSS 50% FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C… Debian Linux 2.6.7.3 / 2.7.9.2+ Fix from $2,3002018-01-10 CRITICAL 9.8 CVE-2015-2320 The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. Debian Linux 3.12.1+ Fix from $2,3002018-01-08 CRITICAL 9.8 CVE-2018-5206 When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer. Debian Linux 1.0.6+ Fix from $2,3002018-01-06 CRITICAL 9.8 CVE-2018-5208 In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. Debian Linux 1.0.6+ Fix from $2,3002018-01-06 CRITICAL 9.8 CVE-2017-1000487EPSS 6% Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings. Debian Linux 3.0.16+ Fix from $2,3002018-01-03 CRITICAL 9.8 CVE-2017-1000501 Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthen… Debian Linux after 7.6.0 Fix from $2,3002018-01-03