Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-1000421
Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
Debian Linux
after 1.89
CRITICAL 9.8
CVE-2014-4914
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…
Debian Linux
1.12.7+
CRITICAL 9.8
CVE-2017-17480EPSS 5%
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2017-17458EPSS 6%
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a …
Debian Linux
4.4.1+
CRITICAL 9.8
CVE-2017-17434
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (i…
Debian Linux
after 3.1.2
CRITICAL 9.8
CVE-2016-1253
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote …
Most
5.0.0a-2.2 / 5.0.0a-2.3+
CRITICAL 9.8
CVE-2017-16943EPSS 44%
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2017-16613EPSS 7%
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …
Debian Linux
after 2.15.1
CRITICAL 9.8
CVE-2017-16840
The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorre…
Debian Linux
Patch available
CRITICAL 10.0
CVE-2017-16845
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
Debian Linux
after 2.11.2
CRITICAL 9.8
CVE-2017-16872
An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cse…
Debian Linux
2.7.1+
CRITICAL 9.1
CVE-2017-8807
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sen…
Debian Linux
4.1.9 / 5.2.1+
CRITICAL 9.8
CVE-2017-8809EPSS 6%
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
Debian Linux
after 1.27.3
CRITICAL 9.1
CVE-2017-1000257EPSS 6%
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl woul…
Debian Linux
after 7.56.0
CRITICAL 9.6
CVE-2017-10285
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u1…
Debian Linux
Patch available
CRITICAL 9.1
CVE-2017-8805
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a…
Ftpsync
after 20171016
CRITICAL 9.8
CVE-2017-0903EPSS 15%
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2017-1000116
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
Debian Linux
4.3+
CRITICAL 9.8
CVE-2017-14632EPSS 6%
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2017-13687
The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-13725
The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-13024
The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-13028
The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-13004
The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-13020
The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-12896
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-12899
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-12902
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
Debian Linux
after 4.9.1
CRITICAL 9.8
CVE-2017-12987
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
Debian Linux
after 4.9.1
CRITICAL 9.1
CVE-2017-14122
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.
Debian Linux
Mitigation only