Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2018-20102

An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS resp…

Fix: after 1.8.14
Fix from $1,950 2018-12-12
Ubuntu Linux HIGH 7.5
CVE-2018-20103EPSS 7%

An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by m…

Fix: after 1.8.14
Fix from $1,950 2018-12-12
Ubuntu Linux HIGH 7.8
CVE-2018-9518

In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escal…

Patch available
Fix from $1,950 2018-12-07
Ubuntu Linux HIGH 8.8
CVE-2018-5810

An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-base…

Fix: 0.18.9+
Fix from $1,950 2018-12-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-5811

An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an …

Fix: 0.18.9+
Fix from $1,600 2018-12-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-5812

An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to trigger a…

Fix: 0.18.9+
Fix from $1,600 2018-12-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-5813

An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a…

Fix: 0.18.11+
Fix from $1,600 2018-12-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-5815

An integer overflow error within the "parse_qt()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigge…

Fix: 0.18.12+
Fix from $1,600 2018-12-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-5816

An integer overflow error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigge…

Fix: 0.18.12+
Fix from $1,600 2018-12-07
Ubuntu Linux HIGH 8.8
CVE-2017-16909

An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a hea…

Fix: 0.18.6+
Fix from $1,950 2018-12-07
Ubuntu Linux HIGH 8.8
CVE-2018-5807

An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-…

Fix: 0.18.9+
Fix from $1,950 2018-12-07
Ubuntu Linux MEDIUM 6.5
CVE-2017-16910

An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause …

Fix: 0.18.6+
Fix from $1,600 2018-12-07
Ubuntu Linux HIGH 7.8
CVE-2018-19931

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based …

Fix: after 2.31
Fix from $1,950 2018-12-07
Ubuntu Linux HIGH 7.8
CVE-2018-9568

In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no add…

Fix: 3.10.108 / 3.16.58+
Fix from $1,950 2018-12-06
Ubuntu Linux MEDIUM 5.5
CVE-2018-19840

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaust…

Fix: after 5.1.0
Fix from $1,600 2018-12-04
Ubuntu Linux MEDIUM 5.5
CVE-2018-19841

The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-…

Fix: after 5.1.0
Fix from $1,600 2018-12-04
Ubuntu Linux HIGH 7.5
CVE-2018-8789EPSS 5%

FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfau…

Fix: after 1.2.0
Fix from $1,950 2018-11-29
Ubuntu Linux CRITICAL 9.8
CVE-2018-8784EPSS 7%

FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption an…

Fix: after 1.2.0
Fix from $2,300 2018-11-29
Ubuntu Linux CRITICAL 9.8
CVE-2018-8785EPSS 7%

FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a memory corruption and probab…

Fix: after 1.2.0
Fix from $2,300 2018-11-29
Ubuntu Linux CRITICAL 9.8
CVE-2018-8786EPSS 8%

FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() …

Patch available
Fix from $2,300 2018-11-29
Ubuntu Linux CRITICAL 9.8
CVE-2018-8787EPSS 8%

FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and re…

Patch available
Fix from $2,300 2018-11-29
Ubuntu Linux CRITICAL 9.8
CVE-2018-8788EPSS 7%

FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption …

Fix: after 1.2.0
Fix from $2,300 2018-11-29
Ubuntu Linux MEDIUM 6.5
CVE-2018-14629EPSS 5%

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-16841

Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card auth…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-16851

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search befor…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Ubuntu Linux HIGH 8.8
CVE-2018-19541

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.1…

No fix yet
Fix from $1,950 2018-11-26
Ubuntu Linux HIGH 7.8
CVE-2018-19543

An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

No fix yet
Fix from $1,950 2018-11-26
Ubuntu Linux MEDIUM 6.5
CVE-2018-19542

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a den…

No fix yet
Fix from $1,600 2018-11-26
Ubuntu Linux MEDIUM 5.5
CVE-2018-18954

The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.

Fix: 3.1+
Fix from $1,600 2018-11-15
Ubuntu Linux MEDIUM 6.5
CVE-2018-19149

Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.

Fix: 0.70.0+
Fix from $1,600 2018-11-10