Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 6.8
CVE-2017-7526

libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right…

Fix: 1.7.8+
Fix from $1,600 2018-07-26
Ubuntu Linux MEDIUM 6.5
CVE-2018-13988

Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demons…

Fix: after 0.62.0
Fix from $1,600 2018-07-25
Ubuntu Linux CRITICAL 9.8
CVE-2018-14551

The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.

No fix yet
Fix from $2,300 2018-07-23
Ubuntu Linux CRITICAL 9.8
CVE-2016-10727

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containin…

Fix: 3.21.2+
Fix from $2,300 2018-07-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-14434

ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.

No fix yet
Fix from $1,600 2018-07-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-14435

ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.

No fix yet
Fix from $1,600 2018-07-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-14436

ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.

No fix yet
Fix from $1,600 2018-07-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-14437

ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.

No fix yet
Fix from $1,600 2018-07-20
Ubuntu Linux CRITICAL 9.8
CVE-2018-12911

WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimec…

Patch available
Fix from $2,300 2018-07-19
Ubuntu Linux MEDIUM 6.5
CVE-2018-14404

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath e…

Fix: after 2.9.8
Fix from $1,600 2018-07-19
Ubuntu Linux MEDIUM 6.5
CVE-2018-10877

Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem…

Patch available
Fix from $1,600 2018-07-18
Ubuntu Linux CRITICAL 9.8
CVE-2018-14351

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14352

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote character…

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14353

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14354EPSS 6%

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…

Patch available
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14357

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…

Patch available
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14358

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi…

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14359

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14362

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with m…

Patch available
Fix from $2,300 2018-07-17
Ubuntu Linux MEDIUM 5.5
CVE-2018-0360

ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_parag…

Fix: 0.100.1+
Fix from $1,600 2018-07-16
Ubuntu Linux MEDIUM 6.5
CVE-2018-13785

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant…

Patch available
Fix from $1,600 2018-07-09
Ubuntu Linux MEDIUM 6.5
CVE-2018-13440

The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker …

No fix yet
Fix from $1,600 2018-07-08
Ubuntu Linux CRITICAL 9.8
CVE-2018-12910

The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

Patch available
Fix from $2,300 2018-07-05
Ubuntu Linux MEDIUM 6.5
CVE-2018-13153

In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.

No fix yet
Fix from $1,600 2018-07-05
Ubuntu Linux MEDIUM 6.1
CVE-2018-0499

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escapi…

Fix: 1.4.6+
Fix from $1,600 2018-07-02
Ubuntu Linux HIGH 7.5
CVE-2018-10860EPSS 49%

perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths wh…

Patch available
Fix from $1,950 2018-06-29
Ubuntu Linux HIGH 7.8
CVE-2018-12931

ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a …

Mitigation only
Fix from $1,950 2018-06-28
Ubuntu Linux HIGH 8.8
CVE-2018-12900EPSS 25%

Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4…

No fix yet
Fix from $1,950 2018-06-26
Ubuntu Linux CRITICAL 9.8
CVE-2018-12699

finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified o…

No fix yet
Fix from $2,300 2018-06-23
Ubuntu Linux HIGH 7.5
CVE-2018-12697EPSS 5%

A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as…

No fix yet
Fix from $1,950 2018-06-23