Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 6.5
CVE-2018-20650

A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data…

Patch available
Fix from $1,600 2019-01-01
Ubuntu Linux HIGH 8.8
CVE-2018-20549

There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.

No fix yet
Fix from $1,950 2018-12-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-20551

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media ann…

Patch available
Fix from $1,600 2018-12-28
Ubuntu Linux HIGH 8.8
CVE-2018-20545

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

Patch available
Fix from $1,950 2018-12-28
Ubuntu Linux HIGH 8.8
CVE-2018-20548

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data.

Patch available
Fix from $1,950 2018-12-28
Ubuntu Linux HIGH 8.1
CVE-2018-20546

There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.

Patch available
Fix from $1,950 2018-12-28
Ubuntu Linux HIGH 8.1
CVE-2018-20547

There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.

Patch available
Fix from $1,950 2018-12-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-20532

There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of s…

Fix: after 0.7.2
Fix from $1,600 2018-12-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-20533

There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a …

Fix: after 0.7.2
Fix from $1,600 2018-12-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-20534

There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties d…

Fix: after 0.7.2
Fix from $1,600 2018-12-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-20544

There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.

No fix yet
Fix from $1,600 2018-12-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-20481

XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL poi…

Patch available
Fix from $1,600 2018-12-26
Ubuntu Linux HIGH 7.5
CVE-2018-20191

hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a d…

Fix: after 3.1.0
Fix from $1,950 2018-12-20
Ubuntu Linux MEDIUM 5.5
CVE-2018-20124

hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.

Fix: after 3.1.0
Fix from $1,600 2018-12-20
Ubuntu Linux HIGH 7.5
CVE-2018-20216

QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).

Fix: after 3.1.0
Fix from $1,950 2018-12-20
Ubuntu Linux HIGH 7.5
CVE-2018-20125

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq…

Fix: after 3.1.0
Fix from $1,950 2018-12-20
Ubuntu Linux MEDIUM 5.5
CVE-2018-20126

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

Fix: after 3.1.0
Fix from $1,600 2018-12-20
Ubuntu Linux HIGH 7.8
CVE-2018-1000876

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_re…

Fix: 2.32+
Fix from $1,950 2018-12-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-1000880

libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vuln…

Fix: 3.4.0+
Fix from $1,600 2018-12-20
Ubuntu Linux HIGH 8.8
CVE-2018-1000858

GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Infor…

Fix: after 2.2.11
Fix from $1,950 2018-12-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-1000852

FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/…

Fix: 2.0.0+
Fix from $1,600 2018-12-20
Ubuntu Linux CRITICAL 9.8
CVE-2018-15126EPSS 12%

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension th…

Fix: 0.9.12+
Fix from $2,300 2018-12-19
Ubuntu Linux CRITICAL 9.8
CVE-2018-15127EPSS 15%

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extensio…

Mitigation only
Fix from $2,300 2018-12-19
Ubuntu Linux CRITICAL 9.8
CVE-2018-20019EPSS 9%

LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can r…

Fix: 0.9.12 / 3.2.1.0+
Fix from $2,300 2018-12-19
Ubuntu Linux CRITICAL 9.8
CVE-2018-20020EPSS 9%

LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that…

Fix: 0.9.12+
Fix from $2,300 2018-12-19
Ubuntu Linux HIGH 8.1
CVE-2018-6307EPSS 27%

LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension th…

Fix: 0.9.12+
Fix from $1,950 2018-12-19
Ubuntu Linux HIGH 7.5
CVE-2018-20021

LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allow…

Fix: 0.9.12+
Fix from $1,950 2018-12-19
Ubuntu Linux HIGH 7.5
CVE-2018-20024

LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.

Fix: 0.9.12+
Fix from $1,950 2018-12-19
Ubuntu Linux MEDIUM 5.5
CVE-2018-20123

pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.

Fix: after 3.1.0
Fix from $1,600 2018-12-17
Ubuntu Linux MEDIUM 5.5
CVE-2018-19364

hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-…

Fix: after 3.0.0
Fix from $1,600 2018-12-13