Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.8
CVE-2019-2054

In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. T…

No fix yet
Fix from $1,950 2019-05-08
Ubuntu Linux HIGH 7.5
CVE-2019-11596

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when …

Fix: 1.5.14+
Fix from $1,950 2019-04-29
Ubuntu Linux HIGH 7.8
CVE-2019-3844

It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would al…

Fix: 242+
Fix from $1,950 2019-04-26
Snapd HIGH 7.5
CVE-2019-11502

snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, tha…

Fix: 2.38+
Fix from $1,950 2019-04-24
Snapd HIGH 7.5
CVE-2019-11503

snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the…

Fix: 2.39+
Fix from $1,950 2019-04-24
Ubuntu Linux MEDIUM 6.5
CVE-2019-11498

WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" co…

Fix: after 5.1.0
Fix from $1,600 2019-04-24
Ubuntu Linux HIGH 8.1
CVE-2019-2697EPSS 11%

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffi…

Patch available
Fix from $1,950 2019-04-23
Snapd CRITICAL 9.8
CVE-2019-7304EPSS 63%

Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This iss…

Fix: 2.37.1+
Fix from $2,300 2019-04-23
Snapd HIGH 7.5
CVE-2019-7303

A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 6…

Fix: 2.37.4+
Fix from $1,950 2019-04-23
Ubuntu Linux MEDIUM 5.5
CVE-2019-11459

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle err…

Fix: after 3.32.0
Fix from $1,600 2019-04-22
Ubuntu Download Manager CRITICAL 9.8
CVE-2016-1579

UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functiona…

Mitigation only
Fix from $2,300 2019-04-22
Apparmor CRITICAL 9.8
CVE-2016-1585

In all versions of AppArmor mount rules are accidentally widened when compiled.

Fix: 2.13.10 / 3.0.12+
Fix from $2,300 2019-04-22
Ubuntu Linux MEDIUM 6.1
CVE-2019-11454

Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbit…

Fix: 5.25.3+
Fix from $1,600 2019-04-22
Metal As A Service CRITICAL 9.8
CVE-2015-1320

The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu M…

Fix: 1.9.2+
Fix from $2,300 2019-04-22
Ubuntu Linux HIGH 7.8
CVE-2015-1341

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Ap…

Fix: 2.19.2+
Fix from $1,950 2019-04-22
Metal As A Service HIGH 7.5
CVE-2014-1426

A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ub…

Fix: 1.9.2+
Fix from $1,950 2019-04-22
Juju HIGH 7.5
CVE-2015-1316

Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.

Fix: 1.25.5+
Fix from $1,950 2019-04-22
Metal As A Service MEDIUM 6.1
CVE-2014-1427

A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue …

Fix: 1.9.2+
Fix from $1,600 2019-04-22
Selinux MEDIUM 5.9
CVE-2011-3151

The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have sym…

Fix: 1+
Fix from $1,600 2019-04-22
Metal As A Service MEDIUM 5.3
CVE-2014-1428

A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior…

Fix: 1.9.2+
Fix from $1,600 2019-04-22
Ubuntu Linux HIGH 7.5
CVE-2019-3885

A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via t…

Fix: after 2.0.1
Fix from $1,950 2019-04-18
Ubuntu Linux HIGH 7.8
CVE-2018-16877

A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could us…

Fix: after 2.0.0
Fix from $1,950 2019-04-18
Ubuntu Linux MEDIUM 5.5
CVE-2018-16878

A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead…

Fix: after 2.0.1
Fix from $1,600 2019-04-18
Ubuntu Linux HIGH 7.5
CVE-2019-9628

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing cla…

Fix: 3.0.4+
Fix from $1,950 2019-04-11
Ubuntu Linux CRITICAL 9.8
CVE-2019-11068EPSS 5%

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving …

Fix: after 1.1.33
Fix from $2,300 2019-04-10
Ubuntu Linux MEDIUM 6.5
CVE-2018-3979

A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader e…

No fix yet
Fix from $1,600 2019-04-01
Ubuntu Linux CRITICAL 9.8
CVE-2019-10269

BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name…

Fix: 2019-01-23+
Fix from $2,300 2019-03-29
Ubuntu Linux HIGH 7.5
CVE-2019-3821

A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create mu…

Fix: 1.11+
Fix from $1,950 2019-03-27
Ubuntu Linux MEDIUM 6.8
CVE-2019-3814

It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a val…

Fix: 2.2.36.1 / 2.3.4.1+
Fix from $1,600 2019-03-27
Ubuntu Linux MEDIUM 6.5
CVE-2019-9917

ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.

Fix: after 1.7.2
Fix from $1,600 2019-03-27