Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2018-12698EPSS 7%

demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka…

No fix yet
Fix from $1,950 2018-06-23
Ubuntu Linux HIGH 7.5
CVE-2018-12617EPSS 25%

qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causin…

Fix: after 2.12.50
Fix from $1,950 2018-06-21
Ubuntu Linux HIGH 8.8
CVE-2018-12599

In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.

No fix yet
Fix from $1,950 2018-06-20
Ubuntu Linux HIGH 8.8
CVE-2018-12600

In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.

No fix yet
Fix from $1,950 2018-06-20
Ubuntu Linux HIGH 8.8
CVE-2018-12293EPSS 11%

The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prio…

Fix: 2.20.1 / 2.20.3+
Fix from $1,950 2018-06-19
Ubuntu Linux MEDIUM 6.5
CVE-2018-1152

libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.

Patch available
Fix from $1,600 2018-06-18
Ubuntu Linux CRITICAL 9.8
CVE-2018-11574

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure,…

Fix: 2.4.9+
Fix from $2,300 2018-06-14
Ubuntu Linux HIGH 8.2
CVE-2018-11806

m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.

Patch available
Fix from $1,950 2018-06-13
Ubuntu Linux HIGH 7.5
CVE-2018-5177

A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow…

Fix: 60.0+
Fix from $1,950 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-5181

If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local fi…

Fix: 60.0+
Fix from $1,950 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-5182

If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local…

Fix: 60.0+
Fix from $1,950 2018-06-11
Ubuntu Linux MEDIUM 6.1
CVE-2018-5175

A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website c…

Fix: 60.0+
Fix from $1,600 2018-06-11
Ubuntu Linux MEDIUM 6.1
CVE-2018-5176

The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains maliciou…

Fix: 60.0+
Fix from $1,600 2018-06-11
Ubuntu Linux HIGH 8.1
CVE-2018-5163

If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data re…

Fix: 60.0+
Fix from $1,950 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-5160

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC en…

Fix: 60.0+
Fix from $1,950 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-5166

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access …

Fix: 60.0+
Fix from $1,950 2018-06-11
Ubuntu Linux MEDIUM 6.5
CVE-2018-5169

If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a…

Fix: 60.0+
Fix from $1,600 2018-06-11
Ubuntu Linux MEDIUM 5.3
CVE-2018-5173

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be use…

Fix: 60.0+
Fix from $1,600 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-5136

A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vu…

Fix: 59.0+
Fix from $1,950 2018-06-11
Ubuntu Linux HIGH 8.8
CVE-2018-5125

Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Ubuntu Linux CRITICAL 9.8
CVE-2018-5089

Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 52.6.0+
Fix from $2,300 2018-06-11
Ubuntu Linux MEDIUM 6.5
CVE-2018-10360

The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and applic…

Patch available
Fix from $1,600 2018-06-11
Ubuntu Linux HIGH 8.8
CVE-2018-12085

Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-114…

Patch available
Fix from $1,950 2018-06-09
Ubuntu Linux HIGH 7.5
CVE-2018-12015EPSS 7%

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary…

Fix: 10.14.4+
Fix from $1,950 2018-06-07
Ubuntu Linux HIGH 8.8
CVE-2018-11683

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-114…

Mitigation only
Fix from $1,950 2018-06-04
Ubuntu Linux HIGH 8.8
CVE-2018-11684

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c.

Mitigation only
Fix from $1,950 2018-06-04
Ubuntu Linux HIGH 8.8
CVE-2018-11685

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c.

Mitigation only
Fix from $1,950 2018-06-04
Ubuntu Linux MEDIUM 6.5
CVE-2018-11655

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows atta…

No fix yet
Fix from $1,600 2018-06-01
Ubuntu Linux MEDIUM 6.5
CVE-2018-11656

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cau…

No fix yet
Fix from $1,600 2018-06-01
Ubuntu Linux HIGH 8.8
CVE-2018-11625

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2018-05-31