Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 5.5
CVE-2020-8831

Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exi…

No fix yet
Fix from $1,600 2020-04-22
Ubuntu Linux HIGH 7.5
CVE-2020-12059

An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exc…

Fix: after 13.2.9
Fix from $1,950 2020-04-22
Ubuntu Linux HIGH 7.8
CVE-2020-11958

re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.

Patch available
Fix from $1,950 2020-04-21
Ubuntu Linux HIGH 8.8
CVE-2020-11793

A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute…

Fix: 2.28.1+
Fix from $1,950 2020-04-17
Ubuntu Linux HIGH 7.5
CVE-2019-7306

Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, u…

No fix yet
Fix from $1,950 2020-04-17
Ubuntu Linux HIGH 7.5
CVE-2019-12520

An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does th…

Fix: after 4.7
Fix from $1,950 2020-04-15
Ubuntu Linux MEDIUM 5.9
CVE-2019-12521EPSS 6%

An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for ho…

Fix: after 5.0.1
Fix from $1,600 2020-04-15
C Kernel HIGH 8.1
CVE-2019-11480

The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options when creating the build chroot e…

Fix: after 2019-07-16
Fix from $1,950 2020-04-14
Ubuntu Linux MEDIUM 5.3
CVE-2020-1730

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or cl…

Fix: 0.8.9 / 0.9.4+
Fix from $1,600 2020-04-13
Ubuntu Linux MEDIUM 5.5
CVE-2020-8832

The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for…

Mitigation only
Fix from $1,600 2020-04-10
Microk8s HIGH 7.8
CVE-2019-15789

Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a priv…

Fix: 1.15.3+
Fix from $1,950 2020-04-08
Ubuntu Linux HIGH 7.4
CVE-2020-11501

GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10…

Fix: 3.6.13+
Fix from $1,950 2020-04-03
Ubuntu Linux HIGH 7.1
CVE-2020-0556

Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege an…

Fix: 5.54+
Fix from $1,950 2020-03-12
Ubuntu Linux MEDIUM 6.5
CVE-2020-6794

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. Thi…

Fix: 68.5.0+
Fix from $1,600 2020-03-02
Ubuntu Linux CRITICAL 9.8
CVE-2020-8794EPSS 89%

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this…

Fix: 6.6.4+
Fix from $2,300 2020-02-25
Ubuntu Linux MEDIUM 6.4
CVE-2020-8130

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character …

Fix: 12.3.3+
Fix from $1,600 2020-02-24
Ubuntu Linux HIGH 8.8
CVE-2020-9308

archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header si…

Fix: 3.4.2+
Fix from $1,950 2020-02-20
Ubuntu Linux HIGH 8.8
CVE-2015-7747EPSS 9%

Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a …

Fix: 0.3.6+
Fix from $1,950 2020-02-19
Ubuntu Linux HIGH 7.8
CVE-2019-11484

Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.

No fix yet
Fix from $1,950 2020-02-08
Ubuntu Linux HIGH 7.8
CVE-2019-11481

Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic …

No fix yet
Fix from $1,950 2020-02-08
Ubuntu Linux HIGH 8.8
CVE-2014-1958

Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code …

Fix: 6.8.8-5+
Fix from $1,950 2020-02-06
Ubuntu Linux HIGH 8.8
CVE-2014-2030EPSS 11%

Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial…

Patch available
Fix from $1,950 2020-02-06
Ubuntu Linux HIGH 7.4
CVE-2016-9928

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity …

Fix: 1.0.4+
Fix from $1,950 2020-02-06
Ubuntu Linux HIGH 7.5
CVE-2020-3123

A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthentica…

Mitigation only
Fix from $1,950 2020-02-05
Cloud Init MEDIUM 5.5
CVE-2020-8631

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str …

Fix: after 19.4
Fix from $1,600 2020-02-05
Cloud Init MEDIUM 5.5
CVE-2020-8632

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for att…

Fix: after 19.4
Fix from $1,600 2020-02-05
Ubuntu Linux HIGH 7.5
CVE-2020-8517EPSS 7%

An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may w…

Fix: 4.10+
Fix from $1,950 2020-02-04
Ubuntu Linux HIGH 7.3
CVE-2020-8450EPSS 72%

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance act…

Fix: 4.10+
Fix from $1,950 2020-02-04
Ubuntu Linux HIGH 7.5
CVE-2019-20421

In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote…

Patch available
Fix from $1,950 2020-01-27
Ubuntu Linux HIGH 8.8
CVE-2016-4761

WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS

Fix: 2.14.0+
Fix from $1,950 2020-01-22