Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 7.5
CVE-2020-14397

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.

Fix: 3.2.1.0+
Fix from $1,950 2020-06-17
Ubuntu Linux HIGH 7.5
CVE-2020-14398

An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.

Fix: 3.2.1.0+
Fix from $1,950 2020-06-17
Ubuntu Linux MEDIUM 5.5
CVE-2020-0543

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable i…

Mitigation only
Fix from $1,600 2020-06-15
Ubuntu Linux MEDIUM 5.9
CVE-2020-14093

Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.

Fix: 1.14.3+
Fix from $1,600 2020-06-15
Ubuntu Linux HIGH 7.5
CVE-2020-0198

In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of servic…

Fix: 0.6.22_p20201105+
Fix from $1,950 2020-06-11
Ubuntu Linux MEDIUM 5.5
CVE-2020-12049

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exc…

Fix: 1.12.18+
Fix from $1,600 2020-06-08
Ubuntu Linux MEDIUM 5.5
CVE-2020-13904

FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, …

Patch available
Fix from $1,600 2020-06-07
Ubuntu Linux MEDIUM 6.0
CVE-2020-13800

ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or a…

Mitigation only
Fix from $1,600 2020-06-04
Ubuntu Linux MEDIUM 5.6
CVE-2020-13765

rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an i…

Patch available
Fix from $1,600 2020-06-04
Ubuntu Linux MEDIUM 6.7
CVE-2020-13754

hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.

Fix: after 5.0.1
Fix from $1,600 2020-06-02
Ubuntu Linux MEDIUM 6.5
CVE-2020-13645

In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if th…

Fix: 2.5.11 / 2.62.4+
Fix from $1,600 2020-05-28
Ubuntu Linux MEDIUM 5.5
CVE-2020-13253

sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS …

Fix: after 5.0.1
Fix from $1,600 2020-05-27
Ubuntu Linux HIGH 8.3
CVE-2020-13398

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/cryp…

Fix: 2.1.1+
Fix from $1,950 2020-05-22
Ubuntu Linux HIGH 7.1
CVE-2020-13396

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/l…

Fix: 2.1.1+
Fix from $1,950 2020-05-22
Ubuntu Linux MEDIUM 5.5
CVE-2020-13397

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/c…

Fix: 2.1.1+
Fix from $1,600 2020-05-22
Ubuntu Linux HIGH 7.5
CVE-2020-13114

An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amoun…

Fix: 0.6.22+
Fix from $1,950 2020-05-21
Ubuntu Linux MEDIUM 6.7
CVE-2020-10722

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a sm…

Fix: after 18.05
Fix from $1,600 2020-05-19
Ubuntu Linux MEDIUM 6.7
CVE-2020-10723

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under c…

Fix: after 17.05
Fix from $1,600 2020-05-19
Ubuntu Linux MEDIUM 6.6
CVE-2020-11524

libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

Fix: 2.0.0+
Fix from $1,600 2020-05-15
Ubuntu Linux MEDIUM 6.6
CVE-2020-11521

libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

Fix: 2.0.0+
Fix from $1,600 2020-05-15
Ubuntu Linux MEDIUM 6.6
CVE-2020-11523

libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.

Fix: 2.0.0+
Fix from $1,600 2020-05-15
Ubuntu Linux MEDIUM 6.5
CVE-2020-11522

libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.

Fix: 2.0.0+
Fix from $1,600 2020-05-15
Ubuntu Linux MEDIUM 5.9
CVE-2020-11047

In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up…

Fix: 2.0.0+
Fix from $1,600 2020-05-07
Ubuntu Linux HIGH 8.8
CVE-2020-12689

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application crede…

Fix: 15.0.1+
Fix from $1,950 2020-05-07
Ubuntu Linux HIGH 8.8
CVE-2020-12691

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a pro…

Fix: 15.0.1+
Fix from $1,950 2020-05-07
Ubuntu Linux MEDIUM 5.4
CVE-2020-12692

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An atta…

Fix: 15.0.1+
Fix from $1,600 2020-05-07
Ubuntu Linux CRITICAL 9.8
CVE-2020-10683EPSS 7%

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…

Fix: 2.0.3 / 2.1.3+
Fix from $2,300 2020-05-01
Ubuntu Linux HIGH 7.0
CVE-2020-1752

A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths co…

Fix: 2.32.0+
Fix from $1,950 2020-04-30
Ubuntu Linux CRITICAL 9.8
CVE-2020-12284

cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of …

Patch available
Fix from $2,300 2020-04-28
Ubuntu Linux CRITICAL 9.8
CVE-2019-20788

libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or wi…

Fix: 3.2.1.0+
Fix from $2,300 2020-04-23