Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux CRITICAL 9.8
CVE-2019-9850

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained …

Fix: 6.2.6+
Fix from $2,300 2019-08-15
Ubuntu Linux CRITICAL 9.8
CVE-2019-9851EPSS 78%

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained …

Fix: 6.2.6+
Fix from $2,300 2019-08-15
Ubuntu Linux HIGH 7.8
CVE-2019-9852

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document…

Fix: 6.2.6+
Fix from $1,950 2019-08-15
Ubuntu Linux HIGH 8.1
CVE-2019-9506

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker fr…

Mitigation only
Fix from $1,950 2019-08-14
Ubuntu Linux MEDIUM 6.5
CVE-2019-14433

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user en…

Fix: 17.0.12 / 18.2.2+
Fix from $1,600 2019-08-09
Ubuntu Linux HIGH 7.8
CVE-2019-14496

LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.

No fix yet
Fix from $1,950 2019-08-01
Ubuntu Linux HIGH 7.8
CVE-2019-14497

ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.

No fix yet
Fix from $1,950 2019-08-01
Ubuntu Linux HIGH 7.5
CVE-2019-14494

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutput…

Fix: after 0.78.0
Fix from $1,950 2019-08-01
Ubuntu Linux MEDIUM 5.5
CVE-2019-14464

XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.

No fix yet
Fix from $1,600 2019-07-31
Ubuntu Linux HIGH 7.5
CVE-2019-14452

Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive en…

Fix: 0.9.16+
Fix from $1,950 2019-07-31
Ubuntu Linux MEDIUM 5.5
CVE-2019-14444

apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_p…

Patch available
Fix from $1,600 2019-07-30
Ubuntu Linux HIGH 7.5
CVE-2019-13565EPSS 5%

An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers…

Fix: 10.13.6 / 10.14.6+
Fix from $1,950 2019-07-26
Ubuntu Linux MEDIUM 5.5
CVE-2019-14250

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a ze…

No fix yet
Fix from $1,600 2019-07-24
Ubuntu Linux MEDIUM 5.3
CVE-2019-2762

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java S…

Patch available
Fix from $1,600 2019-07-23
Ubuntu Linux CRITICAL 9.8
CVE-2019-9848EPSS 31%

LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. …

Fix: 6.2.5+
Fix from $2,300 2019-07-17
Ubuntu Linux HIGH 7.8
CVE-2019-1010006

Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attac…

No fix yet
Fix from $1,950 2019-07-15
Ubuntu Linux HIGH 8.8
CVE-2019-13308

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.

Patch available
Fix from $1,950 2019-07-05
Ubuntu Linux MEDIUM 6.5
CVE-2019-13310

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.

Patch available
Fix from $1,600 2019-07-05
Ubuntu Linux MEDIUM 6.5
CVE-2019-13311

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.

Patch available
Fix from $1,600 2019-07-05
Ubuntu Linux HIGH 7.8
CVE-2019-13241

FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP a…

Fix: after 0.9.2
Fix from $1,950 2019-07-04
Ubuntu Linux MEDIUM 5.5
CVE-2019-12972

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer o…

Patch available
Fix from $1,600 2019-06-26
Ubuntu Linux HIGH 7.0
CVE-2019-12817

arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to…

Fix: 5.1.15+
Fix from $1,950 2019-06-25
Ubuntu Linux HIGH 7.5
CVE-2018-20843EPSS 7%

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amoun…

Fix: 2.2.7+
Fix from $1,950 2019-06-24
Ubuntu Linux MEDIUM 6.5
CVE-2019-12436

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using th…

Fix: 4.10.5+
Fix from $1,600 2019-06-19
Ubuntu Linux HIGH 7.1
CVE-2019-12749

dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less …

Fix: 1.10.28 / 1.12.16+
Fix from $1,950 2019-06-11
Ubuntu Linux CRITICAL 9.8
CVE-2019-10149 KEVEPSS 100%

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c …

Fix: after 4.91
Fix from $2,300 2019-06-05
Ubuntu Linux HIGH 7.3
CVE-2019-12447

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.

Fix: after 1.41.2
Fix from $1,950 2019-05-29
Ubuntu Linux MEDIUM 5.7
CVE-2019-12449

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and …

Fix: after 1.41.2
Fix from $1,600 2019-05-29
Ubuntu Linux HIGH 7.5
CVE-2019-12211

When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destinat…

No fix yet
Fix from $1,950 2019-05-20
Ubuntu Linux MEDIUM 6.5
CVE-2019-12213

When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.

No fix yet
Fix from $1,600 2019-05-20