Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2018-20615 An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The p… Ubuntu Linux after 1.8.19 Fix from $1,9502019-03-21 MEDIUM 6.5 CVE-2019-9721 A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, becaus… Ubuntu Linux Patch available Fix from $1,6002019-03-12 MEDIUM 6.5 CVE-2019-3824 A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An au… Ubuntu Linux 4.10.0+ Fix from $1,6002019-03-06 CRITICAL 9.8 CVE-2019-9169 In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-… Ubuntu Linux 7.7.2.21 / 7.8.2.8+ Fix from $2,3002019-02-26 CRITICAL 9.8 CVE-2019-8375EPSS 16% The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script… Ubuntu Linux after 2.23.90 Fix from $2,3002019-02-24 HIGH 7.8 CVE-2019-9070 An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c… Ubuntu Linux after 5.1.0 Fix from $1,9502019-02-24 HIGH 7.8 CVE-2019-9075 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer over… Ubuntu Linux Patch available Fix from $1,9502019-02-24 HIGH 7.8 CVE-2019-9077 An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option se… Ubuntu Linux after 5.1.0 Fix from $1,9502019-02-24 MEDIUM 5.5 CVE-2019-9071 An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-dema… Ubuntu Linux Patch available Fix from $1,6002019-02-24 MEDIUM 5.5 CVE-2019-9073 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive m… Ubuntu Linux Patch available Fix from $1,6002019-02-24 MEDIUM 5.5 CVE-2019-9074 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read le… Ubuntu Linux Patch available Fix from $1,6002019-02-24 HIGH 8.8 CVE-2019-8904 do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf. Ubuntu Linux No fix yet Fix from $1,9502019-02-18 HIGH 7.8 CVE-2018-20781 In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This … Ubuntu Linux 3.27.2+ Fix from $1,9502019-02-12 CRITICAL 9.8 CVE-2019-3822EPSS 13% libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (… Ubuntu Linux 7.64.0+ Fix from $2,3002019-02-06 HIGH 7.5 CVE-2018-16890EPSS 5% libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages … Ubuntu Linux 7.64.0+ Fix from $1,9502019-02-06 HIGH 7.5 CVE-2019-3823 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the b… Ubuntu Linux 7.64.0+ Fix from $1,9502019-02-06 MEDIUM 6.4 CVE-2019-3825 A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by select… Ubuntu Linux 3.31.4+ Fix from $1,6002019-02-06 MEDIUM 6.5 CVE-2019-1000020 libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Co… Ubuntu Linux 3.4.0+ Fix from $1,6002019-02-04 HIGH 7.8 CVE-2019-7310 In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attacke… Ubuntu Linux No fix yet Fix from $1,9502019-02-03 MEDIUM 6.8 CVE-2019-6109 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker)… Ubuntu Linux after 7.9 Fix from $1,6002019-01-31 MEDIUM 5.9 CVE-2019-6111EPSS 58% An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sen… Ubuntu Linux Patch available Fix from $1,6002019-01-31 CRITICAL 9.8 CVE-2018-20749 LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. Ubuntu Linux 0.9.12 / 3.2.1.0+ Fix from $2,3002019-01-30 CRITICAL 9.8 CVE-2018-20750 LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. Ubuntu Linux 0.9.12 / 3.2.1.0+ Fix from $2,3002019-01-30 HIGH 7.5 CVE-2019-6706EPSS 17% Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a d… Ubuntu Linux Patch available Fix from $1,9502019-01-23 HIGH 7.5 CVE-2018-5738EPSS 11% Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are p… Ubuntu Linux Mitigation only Fix from $1,9502019-01-16 MEDIUM 5.5 CVE-2018-4181 In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions. Ubuntu Linux 10.13.5+ Fix from $1,6002019-01-11 HIGH 8.8 CVE-2019-6128 The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. Ubuntu Linux Patch available Fix from $1,9502019-01-11 CRITICAL 9.8 CVE-2019-5882 Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer. Ubuntu Linux 1.1.2+ Fix from $2,3002019-01-09 HIGH 7.5 CVE-2018-20679EPSS 8% An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a… Ubuntu Linux 1.30.0+ Fix from $1,9502019-01-09 HIGH 7.5 CVE-2019-5747 An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) migh… Ubuntu Linux after 1.30.0 Fix from $1,9502019-01-09