Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2017-15275EPSS 21%

Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.

Fix: 4.5.15 / 4.6.11+
Fix from $1,950 2017-11-27
Ubuntu Linux HIGH 7.8
CVE-2015-7529

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive fi…

Fix: after 3.8
Fix from $1,950 2017-11-06
Ubuntu Linux CRITICAL 9.8
CVE-2017-16548EPSS 5%

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allo…

Fix: after 3.1.2
Fix from $2,300 2017-11-06
Ubuntu Linux HIGH 8.8
CVE-2017-16546

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote …

Patch available
Fix from $1,950 2017-11-05
Ubuntu Linux HIGH 7.5
CVE-2017-15908EPSS 24%

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_pac…

Patch available
Fix from $1,950 2017-10-26
Ubuntu Linux HIGH 8.1
CVE-2017-13082

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during t…

No fix yet
Fix from $1,950 2017-10-17
Ubuntu Linux MEDIUM 6.8
CVE-2017-13084

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, a…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 6.8
CVE-2017-13086

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowi…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13078

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker withi…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13079

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13080

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker with…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13081

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group ke…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13087

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network M…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 5.3
CVE-2017-13088

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireles…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux MEDIUM 6.8
CVE-2017-13077

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allo…

Mitigation only
Fix from $1,600 2017-10-17
Ubuntu Linux HIGH 8.8
CVE-2017-15281

ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspeci…

Patch available
Fix from $1,950 2017-10-12
Ubuntu Linux HIGH 8.8
CVE-2017-2888

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer over…

No fix yet
Fix from $1,950 2017-10-11
Ubuntu Linux MEDIUM 6.5
CVE-2017-15217

ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.

Patch available
Fix from $1,600 2017-10-10
Ubuntu Linux MEDIUM 6.5
CVE-2017-15218

ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.

Patch available
Fix from $1,600 2017-10-10
Ubuntu Linux CRITICAL 9.8
CVE-2017-15032

ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.

Patch available
Fix from $2,300 2017-10-05
Ubuntu Linux HIGH 7.5
CVE-2017-15033

ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c.

Patch available
Fix from $1,950 2017-10-05
Ubuntu Linux HIGH 8.8
CVE-2017-15017

ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/png.c.

Patch available
Fix from $1,950 2017-10-05
Ubuntu Linux HIGH 8.8
CVE-2017-15015

ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDelegateMessage in coders/pdf.c.

Patch available
Fix from $1,950 2017-10-05
Ubuntu Linux HIGH 8.8
CVE-2017-15016

ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadEnhMetaFile in coders/emf.c.

Patch available
Fix from $1,950 2017-10-05
Ubuntu Linux CRITICAL 9.8
CVE-2017-14492EPSS 93%

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte…

Fix: after 2.77
Fix from $2,300 2017-10-03
Ubuntu Linux CRITICAL 9.8
CVE-2017-14493EPSS 84%

Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a craft…

Fix: after 2.77
Fix from $2,300 2017-10-03
Ubuntu Linux HIGH 7.5
CVE-2017-14495EPSS 84%

Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial o…

Fix: after 2.77
Fix from $1,950 2017-10-03
Ubuntu Linux HIGH 7.5
CVE-2017-14496EPSS 66%

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, all…

Fix: after 2.77
Fix from $1,950 2017-10-03
Ubuntu Linux MEDIUM 5.9
CVE-2017-14494EPSS 68%

dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6…

Fix: after 2.77
Fix from $1,600 2017-10-03
Ubuntu Linux HIGH 7.5
CVE-2017-13704EPSS 65%

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is …

Fix: after 2.77
Fix from $1,950 2017-10-03