Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 6.5
CVE-2018-19060

An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by…

No fix yet
Fix from $1,600 2018-11-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-19058

An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.…

No fix yet
Fix from $1,600 2018-11-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-19059

An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonst…

No fix yet
Fix from $1,600 2018-11-07
Ubuntu Linux HIGH 8.4
CVE-2018-9363

In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privile…

Fix: 3.16.58 / 3.18.119+
Fix from $1,950 2018-11-06
Ubuntu Linux HIGH 7.8
CVE-2018-9415

In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalat…

Patch available
Fix from $1,950 2018-11-06
Ubuntu Linux HIGH 7.8
CVE-2018-16847

An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device…

Fix: after 3.0.0
Fix from $1,950 2018-11-02
Ubuntu Linux HIGH 8.1
CVE-2016-6328

A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS)…

Fix: 0.6.22+
Fix from $1,950 2018-10-31
Ubuntu Linux MEDIUM 5.5
CVE-2018-18873

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.

No fix yet
Fix from $1,600 2018-10-31
Ubuntu Linux CRITICAL 9.8
CVE-2018-18751

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram…

No fix yet
Fix from $2,300 2018-10-29
Ubuntu Linux MEDIUM 6.5
CVE-2018-18661

An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c.

Patch available
Fix from $1,600 2018-10-26
Ubuntu Linux HIGH 7.8
CVE-2018-15686

A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be…

Fix: after 239
Fix from $1,950 2018-10-26
Ubuntu Linux HIGH 7.0
CVE-2018-15687

A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are…

Fix: 240+
Fix from $1,950 2018-10-26
Ubuntu Linux HIGH 8.8
CVE-2018-12370

In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded…

Fix: 61.0+
Fix from $1,950 2018-10-18
Ubuntu Linux CRITICAL 9.1
CVE-2018-10933EPSS 92%

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without fir…

Fix: 0.7.6 / 0.8.4+
Fix from $2,300 2018-10-17
Ubuntu Linux MEDIUM 6.5
CVE-2018-10839

Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. I…

Fix: after 3.0.0
Fix from $1,600 2018-10-16
Ubuntu Linux MEDIUM 6.1
CVE-2017-5934

Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web…

Fix: 1.9.10+
Fix from $1,600 2018-10-15
Ubuntu Linux HIGH 7.5
CVE-2018-17958EPSS 6%

Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.

Fix: after 3.0.1
Fix from $1,950 2018-10-09
Ubuntu Linux HIGH 7.5
CVE-2018-17962

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.

No fix yet
Fix from $1,950 2018-10-09
Ubuntu Linux HIGH 8.1
CVE-2018-1000807

Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling tha…

Fix: 17.5.0+
Fix from $1,950 2018-10-08
Ubuntu Linux MEDIUM 5.9
CVE-2018-1000808

Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulner…

Fix: 17.5.0+
Fix from $1,600 2018-10-08
Ubuntu Linux HIGH 7.8
CVE-2018-17407

An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling …

Fix: 2018-09-21+
Fix from $1,950 2018-09-23
Ubuntu Linux HIGH 7.8
CVE-2018-17336

UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents),…

Patch available
Fix from $1,950 2018-09-22
Ubuntu Linux HIGH 7.5
CVE-2018-14645

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resu…

Fix: after 1.8.14
Fix from $1,950 2018-09-21
Ubuntu Linux MEDIUM 6.5
CVE-2018-17294

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to …

Fix: 3.7.0+
Fix from $1,600 2018-09-21
Ubuntu Linux HIGH 7.8
CVE-2018-17183

Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScr…

Mitigation only
Fix from $1,950 2018-09-19
Ubuntu Linux HIGH 8.8
CVE-2018-17095

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overf…

Patch available
Fix from $1,950 2018-09-16
Ubuntu Linux HIGH 7.8
CVE-2018-10853

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current …

Fix: 4.18+
Fix from $1,950 2018-09-11
Ubuntu Linux MEDIUM 6.5
CVE-2018-16749

In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBl…

Fix: 6.9.9-42+
Fix from $1,600 2018-09-09
Ubuntu Linux MEDIUM 6.5
CVE-2018-16750

In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.

Fix: 6.9.9-42+
Fix from $1,600 2018-09-09
Ubuntu Linux MEDIUM 6.6
CVE-2018-0643

Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to…

Mitigation only
Fix from $1,600 2018-09-07