Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-15227EPSS 34% Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters… Debian Linux 2.0.19 / 2.1.13+ Fix from $2,3002020-10-01 CRITICAL 9.8 CVE-2020-24660 An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Host… Debian Linux after 2.0.8 Fix from $2,3002020-09-14 CRITICAL 9.8 CVE-2020-24361 SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec. Debian Linux 1.4.2+ Fix from $2,3002020-08-16 CRITICAL 9.8 CVE-2020-17446 asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server r… Debian Linux 0.21.0+ Fix from $2,3002020-08-12 CRITICAL 9.8 CVE-2020-17368 Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection. Debian Linux after 0.9.62 Fix from $2,3002020-08-11 CRITICAL 9.8 CVE-2020-15866 mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can b… Debian Linux after 2.1.1 Fix from $2,3002020-07-21 CRITICAL 9.1 CVE-2020-15472 In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated … Debian Linux after 3.2 Fix from $2,3002020-07-01 CRITICAL 9.1 CVE-2020-13112 An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash… Debian Linux 0.6.22+ Fix from $2,3002020-05-21 CRITICAL 9.8 CVE-2020-11651 KEVEPSS 97% An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate… Debian Linux 2019.2.4 / 3000.2+ Fix from $2,3002020-04-30 CRITICAL 9.8 CVE-2020-12278EPSS 5% An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate … Debian Linux 0.28.4+ Fix from $2,3002020-04-27 CRITICAL 9.8 CVE-2020-12279EPSS 5% An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short … Debian Linux 0.28.4+ Fix from $2,3002020-04-27 CRITICAL 9.8 CVE-2020-12268 jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow. Debian Linux 0.18+ Fix from $2,3002020-04-27 CRITICAL 9.8 CVE-2020-11945EPSS 27% An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that ar… Debian Linux 4.11 / 5.0.2+ Fix from $2,3002020-04-23 CRITICAL 9.8 CVE-2019-12519EPSS 7% An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function … Debian Linux after 5.0.1 Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2019-12524 An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid… Debian Linux after 4.7 Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2020-11729 An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity… Debian Linux after 0.60 Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2020-10595 pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library… Debian Linux 4.9+ Fix from $2,3002020-03-31 CRITICAL 9.8 CVE-2020-6072 An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels … Debian Linux No fix yet Fix from $2,3002020-03-24 CRITICAL 9.8 CVE-2020-10938EPSS 5% GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c. Debian Linux 1.3.35+ Fix from $2,3002020-03-24 CRITICAL 9.8 CVE-2020-9760 An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buff… Debian Linux 2.7.1+ Fix from $2,3002020-03-23 CRITICAL 9.8 CVE-2020-10232 In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaf… Debian Linux after 4.8.0 Fix from $2,3002020-03-09 CRITICAL 9.8 CVE-2020-9355 danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled. Debian Linux 1.2.11+ Fix from $2,3002020-02-23 CRITICAL 9.8 CVE-2020-8840EPSS 27% FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC… Debian Linux 2.7.9.7 / 2.8.11.5+ Fix from $2,3002020-02-10 CRITICAL 9.8 CVE-2020-8597EPSS 20% eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. Debian Linux 03.04.10+ Fix from $2,3002020-02-03 CRITICAL 9.1 CVE-2019-20444EPSS 9% HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incor… Debian Linux 4.1.44+ Fix from $2,3002020-01-29 CRITICAL 9.1 CVE-2019-20445EPSS 13% HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-En… Debian Linux 4.1.44+ Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2020-7247 KEVEPSS 99% smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as… Debian Linux Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2015-8011EPSS 5% Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (da… Debian Linux 0.8.0+ Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2020-8086 The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f… Debian Linux after 2020-01-27 Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2014-4172EPSS 6% A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.… Debian Linux 1.0.2 / 1.3.3+ Fix from $2,3002020-01-24