Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux CRITICAL 9.1
CVE-2019-17544

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

Fix: 0.60.8+
Fix from $2,300 2019-10-14
Ubuntu Linux MEDIUM 6.5
CVE-2019-17450

find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attac…

No fix yet
Fix from $1,600 2019-10-10
Ubuntu Linux MEDIUM 6.5
CVE-2019-17451

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow lead…

No fix yet
Fix from $1,600 2019-10-10
Ubuntu Linux CRITICAL 9.1
CVE-2019-17134

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass cli…

Fix: 2.1.2 / 3.2.0+
Fix from $2,300 2019-10-08
Ubuntu Linux CRITICAL 9.8
CVE-2019-17266

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properl…

Fix: 2.66.4+
Fix from $2,300 2019-10-06
Ubuntu Linux HIGH 7.5
CVE-2019-16866

Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP addres…

Fix: 1.9.4+
Fix from $1,950 2019-10-03
Ubuntu Linux CRITICAL 9.8
CVE-2019-16928 KEVEPSS 42%

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string…

Fix: after 4.92.2
Fix from $2,300 2019-09-27
Ubuntu Linux MEDIUM 6.5
CVE-2019-9325

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional …

Mitigation only
Fix from $1,600 2019-09-27
Ubuntu Linux HIGH 7.5
CVE-2019-9232EPSS 5%

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Ubuntu Linux MEDIUM 6.3
CVE-2019-13627

It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3…

Mitigation only
Fix from $1,600 2019-09-25
Ubuntu Linux MEDIUM 6.5
CVE-2019-16708

ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.

Patch available
Fix from $1,600 2019-09-23
Ubuntu Linux MEDIUM 6.5
CVE-2019-16709

ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.

Patch available
Fix from $1,600 2019-09-23
Ubuntu Linux MEDIUM 6.5
CVE-2019-16713

ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.

Patch available
Fix from $1,600 2019-09-23
Ubuntu Linux MEDIUM 6.5
CVE-2019-11779

In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately …

Fix: 1.5.9 / 1.6.6+
Fix from $1,600 2019-09-19
Ubuntu Linux MEDIUM 6.5
CVE-2019-16391

SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database…

Fix: 3.1.11 / 3.2.5+
Fix from $1,600 2019-09-17
Ubuntu Linux MEDIUM 6.1
CVE-2019-16392

SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.

Fix: 3.1.11 / 3.2.5+
Fix from $1,600 2019-09-17
Ubuntu Linux MEDIUM 6.1
CVE-2019-16393

SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

Fix: 3.1.11 / 3.2.5+
Fix from $1,600 2019-09-17
Ubuntu Linux HIGH 7.5
CVE-2019-16235

Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.

Fix: 0.1.0+
Fix from $1,950 2019-09-11
Ubuntu Linux HIGH 7.5
CVE-2019-16236

Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.

Fix: 0.1.0+
Fix from $1,950 2019-09-11
Ubuntu Linux HIGH 7.5
CVE-2019-16237

Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.

Fix: 0.1.0+
Fix from $1,950 2019-09-11
Ubuntu Linux HIGH 7.5
CVE-2019-16095

Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.

Patch available
Fix from $1,950 2019-09-08
Ubuntu Linux CRITICAL 9.8
CVE-2019-16092

Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c.

Patch available
Fix from $2,300 2019-09-08
Ubuntu Linux CRITICAL 9.8
CVE-2019-16093

Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.

Patch available
Fix from $2,300 2019-09-08
Ubuntu Linux HIGH 7.5
CVE-2019-16091

Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.

Patch available
Fix from $1,950 2019-09-08
Ubuntu Linux HIGH 7.5
CVE-2019-16094

Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.

Patch available
Fix from $1,950 2019-09-08
Ubuntu Linux HIGH 7.8
CVE-2019-9854

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document…

Fix: 6.2.7 / 6.3.1+
Fix from $1,950 2019-09-06
Ubuntu Linux CRITICAL 9.1
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set i…

Fix: after 4.10.8
Fix from $2,300 2019-09-03
Ubuntu Linux CRITICAL 9.8
CVE-2019-15717

Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.

Fix: 1.2.2+
Fix from $2,300 2019-08-29
Ubuntu Linux MEDIUM 6.5
CVE-2019-15133

In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height f…

Fix: 5.1.7+
Fix from $1,600 2019-08-17
Ubuntu Linux CRITICAL 9.8
CVE-2019-5477EPSS 6%

A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Pro…

Fix: after 1.10.3
Fix from $2,300 2019-08-16