Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 8.8
CVE-2018-11577

Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.

No fix yet
Fix from $1,950 2018-05-31
Ubuntu Linux HIGH 7.5
CVE-2018-11233

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on N…

Fix: after 2.16.3
Fix from $1,950 2018-05-30
Ubuntu Linux MEDIUM 5.9
CVE-2018-11469

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to ac…

Fix: after 1.8.9
Fix from $1,600 2018-05-25
Ubuntu Linux HIGH 8.8
CVE-2018-11440

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.

Mitigation only
Fix from $1,950 2018-05-25
Ubuntu Linux CRITICAL 9.8
CVE-2018-11410EPSS 5%

An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a…

Patch available
Fix from $2,300 2018-05-24
Ubuntu Linux HIGH 7.5
CVE-2018-1123EPSS 9%

procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at th…

Fix: 3.3.15+
Fix from $1,950 2018-05-23
Ubuntu Linux HIGH 7.5
CVE-2018-1125

procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat…

Fix: 3.3.15+
Fix from $1,950 2018-05-23
Ubuntu Linux HIGH 7.0
CVE-2018-1122

procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled di…

Fix: 3.3.15+
Fix from $1,950 2018-05-23
Ubuntu Linux CRITICAL 9.8
CVE-2018-1126

procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw i…

No fix yet
Fix from $2,300 2018-05-23
Ubuntu Linux HIGH 7.8
CVE-2018-1124

procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privi…

Fix: 3.3.15 / 7.6.0+
Fix from $1,950 2018-05-23
Ubuntu Linux MEDIUM 6.5
CVE-2017-18271

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows …

Mitigation only
Fix from $1,600 2018-05-18
Ubuntu Linux MEDIUM 6.5
CVE-2018-10998

An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an i…

No fix yet
Fix from $1,600 2018-05-12
Ubuntu Linux MEDIUM 5.5
CVE-2017-18267

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recu…

Fix: after 0.64.0
Fix from $1,600 2018-05-10
Ubuntu Linux MEDIUM 5.5
CVE-2017-2592

python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could in…

Fix: after 3.23.0
Fix from $1,600 2018-05-08
Ubuntu Linux MEDIUM 6.5
CVE-2018-10804

ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.

Mitigation only
Fix from $1,600 2018-05-08
Ubuntu Linux MEDIUM 6.5
CVE-2018-10805

ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.

Patch available
Fix from $1,600 2018-05-08
Ubuntu Linux MEDIUM 6.5
CVE-2018-10779

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

No fix yet
Fix from $1,600 2018-05-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-10768

There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input wi…

Fix: 0.41.0+
Fix from $1,600 2018-05-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-0494EPSS 17%

GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

Fix: 1.19.5+
Fix from $1,600 2018-05-06
Ubuntu Linux HIGH 8.8
CVE-2018-10528

An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp.

Patch available
Fix from $1,950 2018-04-29
Ubuntu Linux HIGH 8.8
CVE-2018-10529

An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implementation in libraw_x3f.cpp and l…

Patch available
Fix from $1,950 2018-04-29
Ubuntu Linux MEDIUM 6.1
CVE-2018-1059

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Phy…

Mitigation only
Fix from $1,600 2018-04-24
Ubuntu Linux HIGH 8.3
CVE-2018-2825

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult …

Fix: after 11.40
Fix from $1,950 2018-04-19
Ubuntu Linux HIGH 8.3
CVE-2018-2826EPSS 5%

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult …

Fix: after 11.40
Fix from $1,950 2018-04-19
Ubuntu Linux HIGH 7.8
CVE-2018-10194

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows …

Mitigation only
Fix from $1,950 2018-04-18
Ubuntu Linux MEDIUM 6.5
CVE-2018-10177

In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vul…

No fix yet
Fix from $1,600 2018-04-16
Ubuntu Linux HIGH 7.8
CVE-2018-1100

zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this t…

Fix: after 5.4.2
Fix from $1,950 2018-04-11
Ubuntu Linux HIGH 7.8
CVE-2018-9918

libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a de…

Fix: after 8.0.2
Fix from $1,950 2018-04-10
Ubuntu Linux HIGH 7.8
CVE-2018-1000156EPSS 5%

GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed)…

No fix yet
Fix from $1,950 2018-04-06
Ubuntu Linux HIGH 7.1
CVE-2017-13305

A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.

No fix yet
Fix from $1,950 2018-04-04