Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2018-9234

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently…

Mitigation only
Fix from $1,950 2018-04-04
Ubuntu Linux MEDIUM 6.5
CVE-2018-9133

ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of…

No fix yet
Fix from $1,600 2018-03-30
Screen Resolution Extra HIGH 7.0
CVE-2018-8885

screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intend…

Mitigation only
Fix from $1,950 2018-03-28
Ubuntu Linux HIGH 7.8
CVE-2018-1083

Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a sp…

Fix: after 5.4.1
Fix from $1,950 2018-03-28
Ubuntu Linux MEDIUM 5.5
CVE-2018-0202

clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con…

Fix: after 0.99.3
Fix from $1,600 2018-03-27
Ubuntu Linux MEDIUM 6.5
CVE-2017-18251

An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote …

Patch available
Fix from $1,600 2018-03-27
Ubuntu Linux MEDIUM 6.5
CVE-2017-18252

An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (as…

Patch available
Fix from $1,600 2018-03-27
Ubuntu Linux MEDIUM 6.5
CVE-2017-18254

An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote…

Patch available
Fix from $1,600 2018-03-27
Ubuntu Linux HIGH 8.8
CVE-2018-8960

The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer …

No fix yet
Fix from $1,950 2018-03-23
Ubuntu Linux HIGH 7.3
CVE-2018-8881

Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.

Mitigation only
Fix from $1,950 2018-03-20
Ubuntu Linux HIGH 7.5
CVE-2018-1000135

GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DN…

Fix: after 1.10.2
Fix from $1,950 2018-03-20
Ubuntu Linux HIGH 8.8
CVE-2018-8804

WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCore/memory.c double free and a…

Mitigation only
Fix from $1,950 2018-03-20
Ubuntu Linux HIGH 8.8
CVE-2018-1057EPSS 10%

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowi…

Fix: 4.5.16 / 4.6.14+
Fix from $1,950 2018-03-13
Ubuntu Linux HIGH 7.8
CVE-2018-1000097

Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, f…

Mitigation only
Fix from $1,950 2018-03-13
Ubuntu Linux MEDIUM 6.5
CVE-2016-9600

JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially craf…

Fix: 2.0.10+
Fix from $1,600 2018-03-12
Ubuntu Linux MEDIUM 5.3
CVE-2018-7536

An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely…

Fix: 1.8.19 / 1.11.11+
Fix from $1,600 2018-03-09
Ubuntu Linux MEDIUM 5.3
CVE-2018-7537

An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() …

Fix: 1.8.19 / 1.11.11+
Fix from $1,600 2018-03-09
Ubuntu Linux HIGH 7.5
CVE-2018-7182EPSS 29%

The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted…

Patch available
Fix from $1,950 2018-03-06
Ubuntu Linux HIGH 7.5
CVE-2018-7184EPSS 9%

ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of se…

No fix yet
Fix from $1,950 2018-03-06
Ubuntu Linux HIGH 7.5
CVE-2018-7185EPSS 9%

The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet …

Fix: 1.1.6-6931-3 / 2.2.3-1505+
Fix from $1,950 2018-03-06
Ubuntu Linux MEDIUM 5.5
CVE-2018-7728

An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-…

Fix: after 2.4.4
Fix from $1,600 2018-03-06
Ubuntu Linux MEDIUM 5.5
CVE-2018-7729

An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScript_MetaHandler::ParsePSFile() function in XMP…

Fix: after 2.4.4
Fix from $1,600 2018-03-06
Ubuntu Linux MEDIUM 5.5
CVE-2018-7731

An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a bitstream has a NULL value, …

Fix: after 2.4.4
Fix from $1,600 2018-03-06
Ubuntu Linux HIGH 7.8
CVE-2018-1000100

GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap c…

Fix: after 0.7.1
Fix from $1,950 2018-03-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-7725

An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability c…

No fix yet
Fix from $1,600 2018-03-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-7726

An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverag…

No fix yet
Fix from $1,600 2018-03-06
Ubuntu Linux HIGH 7.5
CVE-2018-1000115EPSS 88%

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support …

Patch available
Fix from $1,950 2018-03-05
Ubuntu Linux CRITICAL 9.8
CVE-2017-18211

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-loo…

Patch available
Fix from $2,300 2018-03-01
Ubuntu Linux HIGH 8.8
CVE-2017-18209

In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memo…

Patch available
Fix from $1,950 2018-03-01
Ubuntu Linux CRITICAL 9.8
CVE-2014-10071

In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

Fix: 5.0.7+
Fix from $2,300 2018-02-27