Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux MEDIUM 6.5
CVE-2019-19344

There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions bef…

Fix: 4.9.18 / 4.10.12+
Fix from $1,600 2020-01-21
Ubuntu Linux MEDIUM 5.4
CVE-2019-14902

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, wh…

Fix: 4.9.18 / 4.10.12+
Fix from $1,600 2020-01-21
Ubuntu Linux MEDIUM 5.5
CVE-2019-14615

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user …

No fix yet
Fix from $1,600 2020-01-17
Ubuntu Linux HIGH 7.5
CVE-2020-5390

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected…

Fix: 5.0.0+
Fix from $1,950 2020-01-13
Ubuntu Linux HIGH 7.8
CVE-2013-4532

Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges …

Fix: after 2.1
Fix from $1,950 2020-01-02
Ubuntu Linux HIGH 7.8
CVE-2019-20079

The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.

Fix: 8.1.2136+
Fix from $1,950 2019-12-30
Ubuntu Linux CRITICAL 9.8
CVE-2019-19948

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

Patch available
Fix from $2,300 2019-12-24
Ubuntu Linux HIGH 8.8
CVE-2019-19920

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (r…

Patch available
Fix from $1,950 2019-12-22
Ubuntu Linux HIGH 8.8
CVE-2019-14889

A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a serve…

Fix: 0.8.8 / 0.9.3+
Fix from $1,950 2019-12-10
Ubuntu Cobbler MEDIUM 5.9
CVE-2012-2092

A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG sign…

Fix: 2.2.2+
Fix from $1,600 2019-12-06
Ubuntu Linux HIGH 7.5
CVE-2015-3406

The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as…

Fix: 0.74+
Fix from $1,950 2019-11-29
Ubuntu Linux CRITICAL 9.8
CVE-2019-19330

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa),…

Fix: 2.0.10+
Fix from $2,300 2019-11-27
Ubuntu Linux HIGH 7.5
CVE-2019-18679EPSS 41%

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when pro…

Fix: after 4.8
Fix from $1,950 2019-11-26
Ubuntu Linux HIGH 7.5
CVE-2019-18676EPSS 9%

An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in…

Fix: after 4.8
Fix from $1,950 2019-11-26
Ubuntu Linux MEDIUM 6.1
CVE-2019-18677EPSS 7%

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly inte…

Fix: after 4.8
Fix from $1,600 2019-11-26
Ubuntu Linux MEDIUM 5.3
CVE-2019-18678EPSS 11%

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance …

Fix: after 4.8
Fix from $1,600 2019-11-26
Ubuntu Linux CRITICAL 9.8
CVE-2019-12526EPSS 20%

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a rem…

Fix: after 4.8
Fix from $2,300 2019-11-26
Ubuntu Linux CRITICAL 9.1
CVE-2019-12523

An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through …

Fix: after 4.8
Fix from $2,300 2019-11-26
Cloud Init HIGH 8.8
CVE-2012-6639

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

Fix: 0.7.0+
Fix from $1,950 2019-11-25
Ubuntu Linux HIGH 7.5
CVE-2012-3543

mono 2.10.x ASP.NET Web Form Hash collision DoS

Fix: after 2.10.12
Fix from $1,950 2019-11-21
Ubuntu Linux MEDIUM 5.5
CVE-2015-1607

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows re…

Fix: 1.4.19 / 2.0.27+
Fix from $1,600 2019-11-20
Ubuntu Linux MEDIUM 5.5
CVE-2019-19055

A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to caus…

Fix: after 5.3.11
Fix from $1,600 2019-11-18
Ubuntu Linux MEDIUM 5.5
CVE-2019-0154

Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; I…

Fix: 26.20.100.6859+
Fix from $1,600 2019-11-14
Ubuntu Linux HIGH 7.8
CVE-2019-2214

In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of priv…

No fix yet
Fix from $1,950 2019-11-13
Ubuntu Linux HIGH 7.8
CVE-2019-2201

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead …

Mitigation only
Fix from $1,950 2019-11-13
Ubuntu Linux HIGH 7.8
CVE-2017-5331

Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (pro…

Fix: 0.31.1+
Fix from $1,950 2019-11-04
Ubuntu Linux CRITICAL 9.8
CVE-2019-13508

FreeTDS through 1.1.11 has a Buffer Overflow.

Fix: after 1.1.11
Fix from $2,300 2019-10-31
Ubuntu Linux HIGH 7.5
CVE-2019-15681

LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read st…

Fix: 0.9.12 / 3.2.1.0+
Fix from $1,950 2019-10-29
Ubuntu Linux HIGH 7.5
CVE-2019-18197

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to…

Patch available
Fix from $1,950 2019-10-18
Ubuntu Linux CRITICAL 9.8
CVE-2019-17542

FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.

Fix: 2.8.16 / 3.2.15+
Fix from $2,300 2019-10-14