Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-1000421 Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution Debian Linux after 1.89 Fix from $2,3002018-01-02 CRITICAL 9.8 CVE-2014-4914 The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL… Debian Linux 1.12.7+ Fix from $2,3002017-12-29 CRITICAL 9.8 CVE-2017-17480EPSS 5% In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou… Debian Linux Mitigation only Fix from $2,3002017-12-08 CRITICAL 9.8 CVE-2017-17458EPSS 6% In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a … Debian Linux 4.4.1+ Fix from $2,3002017-12-07 CRITICAL 9.8 CVE-2017-17434 The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (i… Debian Linux after 3.1.2 Fix from $2,3002017-12-06 CRITICAL 9.8 CVE-2016-1253 The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote … Most 5.0.0a-2.2 / 5.0.0a-2.3+ Fix from $2,3002017-12-05 CRITICAL 9.8 CVE-2017-16943EPSS 44% The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of… Debian Linux Patch available Fix from $2,3002017-11-25 CRITICAL 9.8 CVE-2017-16613EPSS 7% An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and … Debian Linux after 2.15.1 Fix from $2,3002017-11-21 CRITICAL 9.8 CVE-2017-16840 The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorre… Debian Linux Patch available Fix from $2,3002017-11-21 CRITICAL 10.0 CVE-2017-16845 hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. Debian Linux after 2.11.2 Fix from $2,3002017-11-17 CRITICAL 9.8 CVE-2017-16872 An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cse… Debian Linux 2.7.1+ Fix from $2,3002017-11-17 CRITICAL 9.1 CVE-2017-8807 vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sen… Debian Linux 4.1.9 / 5.2.1+ Fix from $2,3002017-11-16 CRITICAL 9.8 CVE-2017-8809EPSS 6% api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability. Debian Linux after 1.27.3 Fix from $2,3002017-11-15 CRITICAL 9.1 CVE-2017-1000257EPSS 6% An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl woul… Debian Linux after 7.56.0 Fix from $2,3002017-10-31 CRITICAL 9.6 CVE-2017-10285 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u1… Debian Linux Patch available Fix from $2,3002017-10-19 CRITICAL 9.1 CVE-2017-8805 Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a… Ftpsync after 20171016 Fix from $2,3002017-10-17 CRITICAL 9.8 CVE-2017-0903EPSS 15% RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio… Debian Linux Patch available Fix from $2,3002017-10-11 CRITICAL 9.8 CVE-2017-1000116 Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks. Debian Linux 4.3+ Fix from $2,3002017-10-05 CRITICAL 9.8 CVE-2017-14632EPSS 6% Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi… Debian Linux Mitigation only Fix from $2,3002017-09-21 CRITICAL 9.8 CVE-2017-13687 The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-13725 The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-13024 The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-13028 The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-13004 The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-13020 The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-12896 The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-12899 The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-12902 The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions. Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-12987 The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements(). Debian Linux after 4.9.1 Fix from $2,3002017-09-14 CRITICAL 9.1 CVE-2017-14122 unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp. Debian Linux Mitigation only Fix from $2,3002017-09-03