Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2018-20615

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The p…

Fix: after 1.8.19
Fix from $1,950 2019-03-21
Ubuntu Linux MEDIUM 6.5
CVE-2019-9721

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, becaus…

Patch available
Fix from $1,600 2019-03-12
Ubuntu Linux MEDIUM 6.5
CVE-2019-3824

A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An au…

Fix: 4.10.0+
Fix from $1,600 2019-03-06
Ubuntu Linux CRITICAL 9.8
CVE-2019-9169

In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-…

Fix: 7.7.2.21 / 7.8.2.8+
Fix from $2,300 2019-02-26
Ubuntu Linux CRITICAL 9.8
CVE-2019-8375EPSS 16%

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script…

Fix: after 2.23.90
Fix from $2,300 2019-02-24
Ubuntu Linux HIGH 7.8
CVE-2019-9070

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c…

Fix: after 5.1.0
Fix from $1,950 2019-02-24
Ubuntu Linux HIGH 7.8
CVE-2019-9075

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer over…

Patch available
Fix from $1,950 2019-02-24
Ubuntu Linux HIGH 7.8
CVE-2019-9077

An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option se…

Fix: after 5.1.0
Fix from $1,950 2019-02-24
Ubuntu Linux MEDIUM 5.5
CVE-2019-9071

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-dema…

Patch available
Fix from $1,600 2019-02-24
Ubuntu Linux MEDIUM 5.5
CVE-2019-9073

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive m…

Patch available
Fix from $1,600 2019-02-24
Ubuntu Linux MEDIUM 5.5
CVE-2019-9074

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read le…

Patch available
Fix from $1,600 2019-02-24
Ubuntu Linux HIGH 8.8
CVE-2019-8904

do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.

No fix yet
Fix from $1,950 2019-02-18
Ubuntu Linux HIGH 7.8
CVE-2018-20781

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This …

Fix: 3.27.2+
Fix from $1,950 2019-02-12
Ubuntu Linux CRITICAL 9.8
CVE-2019-3822EPSS 13%

libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (…

Fix: 7.64.0+
Fix from $2,300 2019-02-06
Ubuntu Linux HIGH 7.5
CVE-2018-16890EPSS 5%

libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages …

Fix: 7.64.0+
Fix from $1,950 2019-02-06
Ubuntu Linux HIGH 7.5
CVE-2019-3823

libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the b…

Fix: 7.64.0+
Fix from $1,950 2019-02-06
Ubuntu Linux MEDIUM 6.4
CVE-2019-3825

A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by select…

Fix: 3.31.4+
Fix from $1,600 2019-02-06
Ubuntu Linux MEDIUM 6.5
CVE-2019-1000020

libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Co…

Fix: 3.4.0+
Fix from $1,600 2019-02-04
Ubuntu Linux HIGH 7.8
CVE-2019-7310

In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attacke…

No fix yet
Fix from $1,950 2019-02-03
Ubuntu Linux MEDIUM 6.8
CVE-2019-6109

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker)…

Fix: after 7.9
Fix from $1,600 2019-01-31
Ubuntu Linux MEDIUM 5.9
CVE-2019-6111EPSS 58%

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sen…

Patch available
Fix from $1,600 2019-01-31
Ubuntu Linux CRITICAL 9.8
CVE-2018-20749

LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Fix: 0.9.12 / 3.2.1.0+
Fix from $2,300 2019-01-30
Ubuntu Linux CRITICAL 9.8
CVE-2018-20750

LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Fix: 0.9.12 / 3.2.1.0+
Fix from $2,300 2019-01-30
Ubuntu Linux HIGH 7.5
CVE-2019-6706EPSS 17%

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a d…

Patch available
Fix from $1,950 2019-01-23
Ubuntu Linux HIGH 7.5
CVE-2018-5738EPSS 11%

Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are p…

Mitigation only
Fix from $1,950 2019-01-16
Ubuntu Linux MEDIUM 5.5
CVE-2018-4181

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

Fix: 10.13.5+
Fix from $1,600 2019-01-11
Ubuntu Linux HIGH 8.8
CVE-2019-6128

The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

Patch available
Fix from $1,950 2019-01-11
Ubuntu Linux CRITICAL 9.8
CVE-2019-5882

Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.

Fix: 1.1.2+
Fix from $2,300 2019-01-09
Ubuntu Linux HIGH 7.5
CVE-2018-20679EPSS 8%

An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a…

Fix: 1.30.0+
Fix from $1,950 2019-01-09
Ubuntu Linux HIGH 7.5
CVE-2019-5747

An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) migh…

Fix: after 1.30.0
Fix from $1,950 2019-01-09