Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2017-7526 libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right… Ubuntu Linux 1.7.8+ Fix from $1,6002018-07-26 MEDIUM 6.5 CVE-2018-13988 Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demons… Ubuntu Linux after 0.62.0 Fix from $1,6002018-07-25 CRITICAL 9.8 CVE-2018-14551 The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption. Ubuntu Linux No fix yet Fix from $2,3002018-07-23 CRITICAL 9.8 CVE-2016-10727 camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containin… Ubuntu Linux 3.21.2+ Fix from $2,3002018-07-20 MEDIUM 6.5 CVE-2018-14434 ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c. Ubuntu Linux No fix yet Fix from $1,6002018-07-20 MEDIUM 6.5 CVE-2018-14435 ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c. Ubuntu Linux No fix yet Fix from $1,6002018-07-20 MEDIUM 6.5 CVE-2018-14436 ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c. Ubuntu Linux No fix yet Fix from $1,6002018-07-20 MEDIUM 6.5 CVE-2018-14437 ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c. Ubuntu Linux No fix yet Fix from $1,6002018-07-20 CRITICAL 9.8 CVE-2018-12911 WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimec… Ubuntu Linux Patch available Fix from $2,3002018-07-19 MEDIUM 6.5 CVE-2018-14404 A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath e… Ubuntu Linux after 2.9.8 Fix from $1,6002018-07-19 MEDIUM 6.5 CVE-2018-10877 Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem… Ubuntu Linux Patch available Fix from $1,6002018-07-18 CRITICAL 9.8 CVE-2018-14351 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size. Ubuntu Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14352 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote character… Ubuntu Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14353 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow. Ubuntu Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14354EPSS 6% An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo… Ubuntu Linux Patch available Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14357 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo… Ubuntu Linux Patch available Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14358 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi… Ubuntu Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14359 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data. Ubuntu Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14362 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with m… Ubuntu Linux Patch available Fix from $2,3002018-07-17 MEDIUM 5.5 CVE-2018-0360 ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_parag… Ubuntu Linux 0.100.1+ Fix from $1,6002018-07-16 MEDIUM 6.5 CVE-2018-13785 In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant… Ubuntu Linux Patch available Fix from $1,6002018-07-09 MEDIUM 6.5 CVE-2018-13440 The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker … Ubuntu Linux No fix yet Fix from $1,6002018-07-08 CRITICAL 9.8 CVE-2018-12910 The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. Ubuntu Linux Patch available Fix from $2,3002018-07-05 MEDIUM 6.5 CVE-2018-13153 In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c. Ubuntu Linux No fix yet Fix from $1,6002018-07-05 MEDIUM 6.1 CVE-2018-0499 A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escapi… Ubuntu Linux 1.4.6+ Fix from $1,6002018-07-02 HIGH 7.5 CVE-2018-10860EPSS 49% perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths wh… Ubuntu Linux Patch available Fix from $1,9502018-06-29 HIGH 7.8 CVE-2018-12931 ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a … Ubuntu Linux Mitigation only Fix from $1,9502018-06-28 HIGH 8.8 CVE-2018-12900EPSS 25% Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4… Ubuntu Linux No fix yet Fix from $1,9502018-06-26 CRITICAL 9.8 CVE-2018-12699 finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified o… Ubuntu Linux No fix yet Fix from $2,3002018-06-23 HIGH 7.5 CVE-2018-12697EPSS 5% A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as… Ubuntu Linux No fix yet Fix from $1,9502018-06-23