Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 6.5
CVE-2018-16643

The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in Image…

Patch available
Fix from $1,600 2018-09-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-16644

There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which a…

Patch available
Fix from $1,600 2018-09-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-16645

There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11,…

Patch available
Fix from $1,600 2018-09-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-16640

ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c.

Patch available
Fix from $1,600 2018-09-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-16642

The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to a…

Patch available
Fix from $1,600 2018-09-06
Ubuntu Linux HIGH 7.8
CVE-2018-16585

An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for u…

Fix: 9.24+
Fix from $1,950 2018-09-06
Ubuntu Linux CRITICAL 9.8
CVE-2018-14618EPSS 11%

curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multipl…

Fix: 7.61.1+
Fix from $2,300 2018-09-05
Ubuntu Linux HIGH 7.8
CVE-2018-16543

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

Fix: 9.24+
Fix from $1,950 2018-09-05
Ubuntu Linux MEDIUM 5.5
CVE-2018-16539

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to di…

Patch available
Fix from $1,600 2018-09-05
Ubuntu Linux MEDIUM 5.5
CVE-2018-16541

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to cra…

Patch available
Fix from $1,600 2018-09-05
Ubuntu Linux HIGH 7.8
CVE-2018-16513

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash th…

Fix: 8.2r12.1 / 8.3r7.1+
Fix from $1,950 2018-09-05
Ubuntu Linux CRITICAL 9.8
CVE-2018-0502

An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named…

Fix: 5.6+
Fix from $2,300 2018-09-05
Ubuntu Linux CRITICAL 9.8
CVE-2018-13259

An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program n…

Fix: 5.6+
Fix from $2,300 2018-09-05
Ubuntu Linux HIGH 7.8
CVE-2018-16510

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote…

Fix: 9.24 / 9.26+
Fix from $1,950 2018-09-05
Ubuntu Linux MEDIUM 5.5
CVE-2018-16435

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based bu…

Patch available
Fix from $1,600 2018-09-04
Ubuntu Linux CRITICAL 9.8
CVE-2018-16428

In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.

Patch available
Fix from $2,300 2018-09-04
Ubuntu Linux HIGH 7.5
CVE-2018-16429

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

Patch available
Fix from $1,950 2018-09-04
Ubuntu Linux MEDIUM 6.5
CVE-2018-16336

Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craf…

Mitigation only
Fix from $1,600 2018-09-02
Ubuntu Linux MEDIUM 6.5
CVE-2018-16323EPSS 49%

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If …

Fix: 6.9.10-9 / 7.0.8-9+
Fix from $1,600 2018-09-01
Ubuntu Linux HIGH 7.5
CVE-2018-14622

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all ins…

Fix: 0.3.3+
Fix from $1,950 2018-08-30
Ubuntu Linux HIGH 7.8
CVE-2018-16140

A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a cra…

Mitigation only
Fix from $1,950 2018-08-30
Ubuntu Linux MEDIUM 5.5
CVE-2018-15858

Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15859

Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attacker…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15861

Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer de…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15862

Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer der…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15863

Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NUL…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15864

Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer …

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux HIGH 7.8
CVE-2018-15857

An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon key…

Fix: 0.8.1+
Fix from $1,950 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15853

Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon user…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15854

Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by s…

Fix: 0.8.1+
Fix from $1,600 2018-08-25