Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.8
CVE-2020-15861

Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.

Fix: after 5.7.3
Fix from $1,950 2020-08-20
Ubuntu Linux HIGH 7.8
CVE-2020-15862

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as …

Fix: 5.8.1+
Fix from $1,950 2020-08-20
Apport HIGH 7.0
CVE-2020-15702

TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the cra…

Mitigation only
Fix from $1,950 2020-08-06
Whoopsie MEDIUM 5.5
CVE-2020-11937

In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource ex…

No fix yet
Fix from $1,600 2020-08-06
Apport MEDIUM 5.5
CVE-2020-15701

An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribu…

No fix yet
Fix from $1,600 2020-08-06
Snapd MEDIUM 6.8
CVE-2020-11933

cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker cou…

Fix: 2.45.2+
Fix from $1,600 2020-07-29
Ubuntu Linux MEDIUM 5.9
CVE-2020-11934

It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in user…

Mitigation only
Fix from $1,600 2020-07-29
Ubuntu Linux CRITICAL 9.8
CVE-2020-15900EPSS 5%

A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file acce…

Patch available
Fix from $2,300 2020-07-28
Trust Store \(ubuntu\) MEDIUM 5.0
CVE-2014-1422

In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the applic…

Fix: 1.1.0+
Fix from $1,600 2020-07-22
Ubuntu Linux HIGH 7.5
CVE-2020-3481

A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remo…

Fix: after 0.102.3
Fix from $1,950 2020-07-20
Ubuntu Linux HIGH 7.2
CVE-2020-14678

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 …

Fix: after 8.0.20
Fix from $1,950 2020-07-15
Ubuntu Linux MEDIUM 6.5
CVE-2020-14680

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. …

Fix: after 8.0.20
Fix from $1,600 2020-07-15
Ubuntu Linux HIGH 7.2
CVE-2020-14663

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 …

Fix: after 8.0.20
Fix from $1,950 2020-07-15
Ubuntu Linux MEDIUM 5.5
CVE-2020-14651

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supported versions that are affected are 8.0.20 and p…

Fix: after 8.0.20
Fix from $1,600 2020-07-15
Ubuntu Linux MEDIUM 5.5
CVE-2020-14643

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supported versions that are affected are 8.0.20 and p…

Fix: after 8.0.20
Fix from $1,600 2020-07-15
Ubuntu Linux HIGH 7.5
CVE-2020-12398

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unen…

Fix: 68.9.0+
Fix from $1,950 2020-07-09
Ubuntu Linux MEDIUM 6.5
CVE-2020-10760

A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samb…

Fix: 4.10.17 / 4.11.11+
Fix from $1,600 2020-07-06
Ubuntu Linux CRITICAL 9.8
CVE-2017-18922

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could expl…

Fix: 0.9.12 / 3.2.1.0+
Fix from $2,300 2020-06-30
Ubuntu Linux HIGH 7.8
CVE-2020-5963

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control m…

Fix: 390.138 / 392.61+
Fix from $1,950 2020-06-25
Ubuntu Linux HIGH 8.0
CVE-2020-12865

A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbit…

Fix: 1.0.30+
Fix from $1,950 2020-06-24
Ubuntu Linux MEDIUM 5.7
CVE-2020-12866

A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a deni…

Fix: 1.0.30+
Fix from $1,600 2020-06-24
Ubuntu Linux HIGH 8.8
CVE-2020-12861

A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrar…

Fix: 1.0.30+
Fix from $1,950 2020-06-24
Ubuntu Linux MEDIUM 6.5
CVE-2020-14405

An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.

Fix: 0.9.12 / 3.2.1.0+
Fix from $1,600 2020-06-17
Ubuntu Linux MEDIUM 5.4
CVE-2020-14402

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.

Fix: 3.2.1.0+
Fix from $1,600 2020-06-17
Ubuntu Linux MEDIUM 5.4
CVE-2020-14403

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.

Fix: 3.2.1.0+
Fix from $1,600 2020-06-17
Ubuntu Linux MEDIUM 5.4
CVE-2020-14404

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.

Fix: 0.9.12 / 3.2.1.0+
Fix from $1,600 2020-06-17
Ubuntu Linux HIGH 7.5
CVE-2018-21247

An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c…

Fix: 3.2.1.0+
Fix from $1,950 2020-06-17
Ubuntu Linux HIGH 7.5
CVE-2019-20839

libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.

Fix: 3.2.1.0+
Fix from $1,950 2020-06-17
Ubuntu Linux HIGH 7.5
CVE-2019-20840

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecod…

Fix: 3.2.1.0+
Fix from $1,950 2020-06-17
Ubuntu Linux HIGH 7.5
CVE-2020-14396

An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.

Fix: 3.2.1.0+
Fix from $1,950 2020-06-17