Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux CRITICAL 9.8
CVE-2016-10714

In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.

Fix: 5.3+
Fix from $2,300 2018-02-27
Ubuntu Linux CRITICAL 9.8
CVE-2017-18206

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

Fix: 5.4+
Fix from $2,300 2018-02-27
Ubuntu Linux CRITICAL 9.8
CVE-2018-7548

In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.

Fix: after 5.4.2
Fix from $2,300 2018-02-27
Ubuntu Linux HIGH 7.5
CVE-2018-5381EPSS 30%

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capabili…

Fix: 2.13.0+
Fix from $1,950 2018-02-19
Ubuntu Linux CRITICAL 9.8
CVE-2018-7054

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE:…

Fix: 1.0.7+
Fix from $2,300 2018-02-15
Ubuntu Linux HIGH 7.5
CVE-2018-7052

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL p…

Fix: 1.0.7+
Fix from $1,950 2018-02-15
Ubuntu Linux HIGH 7.8
CVE-2018-6954

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of …

Fix: after 237
Fix from $1,950 2018-02-13
Ubuntu Linux HIGH 7.5
CVE-2018-6951EPSS 8%

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of…

Fix: after 2.7.6
Fix from $1,950 2018-02-13
Ubuntu Linux MEDIUM 6.5
CVE-2018-6942

An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS …

Fix: after 2.9
Fix from $1,600 2018-02-13
Ubuntu Linux MEDIUM 5.5
CVE-2017-10689

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a f…

Fix: 1.10.10 / 5.3.4+
Fix from $1,600 2018-02-09
Ubuntu Linux HIGH 7.8
CVE-2017-14177

Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker…

Fix: after 2.20.7
Fix from $1,950 2018-02-02
Ubuntu Linux HIGH 7.8
CVE-2017-14179

Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an at…

Fix: 2.13+
Fix from $1,950 2018-02-02
Ubuntu Linux HIGH 7.8
CVE-2017-14180

Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root whi…

Fix: after 2.20.7
Fix from $1,950 2018-02-02
Ubuntu Linux MEDIUM 6.5
CVE-2018-6540

In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote atta…

No fix yet
Fix from $1,600 2018-02-02
Ubuntu Linux MEDIUM 6.5
CVE-2018-6541

In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_…

No fix yet
Fix from $1,600 2018-02-02
Ubuntu Linux MEDIUM 6.5
CVE-2018-6484

In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could l…

No fix yet
Fix from $1,600 2018-02-01
Ubuntu Linux HIGH 7.8
CVE-2018-1000001EPSS 13%

In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading …

No fix yet
Fix from $1,950 2018-01-31
Ubuntu Linux MEDIUM 6.5
CVE-2018-6405

In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new …

Fix: 6.9.9-35 / 7.0.7-23+
Fix from $1,600 2018-01-30
Ubuntu Linux MEDIUM 6.5
CVE-2018-6381

In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a segmentation faul…

No fix yet
Fix from $1,600 2018-01-29
Ubuntu Linux HIGH 7.5
CVE-2018-6196

w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a neg…

Fix: after 0.5.3
Fix from $1,950 2018-01-25
Ubuntu Linux HIGH 7.5
CVE-2018-6197

w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.

Fix: after 0.5.3
Fix from $1,950 2018-01-25
Ubuntu Linux MEDIUM 6.5
CVE-2017-18027

In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause…

No fix yet
Fix from $1,600 2018-01-12
Ubuntu Linux MEDIUM 6.5
CVE-2017-18028

In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers …

No fix yet
Fix from $1,600 2018-01-12
Ubuntu Linux MEDIUM 6.5
CVE-2017-18029

In ImageMagick 7.0.6-10 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to caus…

No fix yet
Fix from $1,600 2018-01-12
Ubuntu Linux MEDIUM 6.5
CVE-2018-5357

ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.

No fix yet
Fix from $1,600 2018-01-12
Ubuntu Linux MEDIUM 6.5
CVE-2018-5358

ImageMagick 7.0.7-22 Q16 has memory leaks in the EncodeImageAttributes function in coders/json.c, as demonstrated by the ReadPSDLayersInternal functi…

No fix yet
Fix from $1,600 2018-01-12
Ubuntu Linux MEDIUM 6.5
CVE-2017-18022

In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.

No fix yet
Fix from $1,600 2018-01-05
Ubuntu Linux MEDIUM 6.5
CVE-2018-5246

In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadPATTERNImage in coders/pattern.c.

No fix yet
Fix from $1,600 2018-01-05
Ubuntu Linux MEDIUM 6.5
CVE-2018-5247

In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadRLAImage in coders/rla.c.

No fix yet
Fix from $1,600 2018-01-05
Ubuntu Linux MEDIUM 5.6
CVE-2017-5715EPSS 74%

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an at…

Patch available
Fix from $1,600 2018-01-04