Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.5
CVE-2018-15855

Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by s…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15856

An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attacker…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Ubuntu Linux CRITICAL 9.8
CVE-2018-14599

An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious s…

Fix: after 1.6.5
Fix from $2,300 2018-08-24
Ubuntu Linux CRITICAL 9.8
CVE-2018-14600EPSS 9%

An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resul…

Fix: after 1.6.5
Fix from $2,300 2018-08-24
Ubuntu Linux HIGH 7.5
CVE-2018-14598

An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overfl…

Fix: after 1.6.5
Fix from $1,950 2018-08-24
Ubuntu Linux MEDIUM 6.5
CVE-2018-15120EPSS 11%

libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application cra…

Fix: after 1.42.3
Fix from $1,600 2018-08-24
Ubuntu Linux MEDIUM 6.5
CVE-2018-10918

A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use …

Fix: 4.7.9 / 4.8.4+
Fix from $1,600 2018-08-22
Ubuntu Linux MEDIUM 6.5
CVE-2018-10919

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated at…

Fix: 4.6.16 / 4.7.9+
Fix from $1,600 2018-08-22
Ubuntu Linux HIGH 8.1
CVE-2018-1139

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A ma…

Fix: 4.7.9 / 4.8.4+
Fix from $1,950 2018-08-22
Ubuntu Linux HIGH 7.0
CVE-2018-6557

The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled te…

Mitigation only
Fix from $1,950 2018-08-21
Ubuntu Linux MEDIUM 5.9
CVE-2018-0501

The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verifica…

Fix: 1.6.4+
Fix from $1,600 2018-08-21
Ubuntu Linux HIGH 8.8
CVE-2018-1000222

Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This atta…

Mitigation only
Fix from $1,950 2018-08-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-14567

libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA…

Patch available
Fix from $1,600 2018-08-16
Ubuntu Linux HIGH 8.8
CVE-2018-6553

The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape c…

Mitigation only
Fix from $1,950 2018-08-10
Ubuntu Linux HIGH 8.1
CVE-2018-10925

It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statemen…

Fix: 9.5.14 / 9.6.10+
Fix from $1,950 2018-08-09
Ubuntu Linux MEDIUM 6.5
CVE-2018-14526

An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not che…

Fix: after 2.6
Fix from $1,600 2018-08-08
Ubuntu Linux MEDIUM 5.5
CVE-2018-7073

A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

Fix: 1.24+
Fix from $1,600 2018-08-06
Ubuntu Linux CRITICAL 9.1
CVE-2018-14938

An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during cap…

Fix: after 1.4.5
Fix from $2,300 2018-08-05
Cloud Init HIGH 7.1
CVE-2018-10896

The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. …

Fix: 18.4+
Fix from $1,950 2018-08-01
Ubuntu Linux MEDIUM 6.5
CVE-2018-10916

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on th…

Fix: after 4.8.3
Fix from $1,600 2018-08-01
Ubuntu Linux HIGH 7.5
CVE-2016-9597

It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml…

Mitigation only
Fix from $1,950 2018-07-30
Ubuntu Linux HIGH 8.8
CVE-2018-14681

An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or tw…

Fix: after 1.5
Fix from $1,950 2018-07-28
Ubuntu Linux HIGH 8.8
CVE-2018-14682

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.

Fix: after 1.5
Fix from $1,950 2018-07-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-14679

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks…

Fix: after 1.5
Fix from $1,600 2018-07-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-14680

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.

Fix: after 1.5
Fix from $1,600 2018-07-28
Ubuntu Linux CRITICAL 9.8
CVE-2017-15118EPSS 12%

A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of…

Fix: 2.11+
Fix from $2,300 2018-07-27
Ubuntu Linux HIGH 7.8
CVE-2018-1056

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potenti…

Fix: 2.1+
Fix from $1,950 2018-07-27
Ubuntu Linux HIGH 7.8
CVE-2018-10878

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other im…

Fix: 3.16.58 / 3.18.124+
Fix from $1,950 2018-07-26
Ubuntu Linux HIGH 7.8
CVE-2018-10879

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of serv…

Fix: 4.17.6+
Fix from $1,950 2018-07-26
Ubuntu Linux MEDIUM 5.5
CVE-2018-10881

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of se…

Fix: 4.17.6+
Fix from $1,600 2018-07-26