Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2018-12698EPSS 7% demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka… Ubuntu Linux No fix yet Fix from $1,9502018-06-23 HIGH 7.5 CVE-2018-12617EPSS 25% qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causin… Ubuntu Linux after 2.12.50 Fix from $1,9502018-06-21 HIGH 8.8 CVE-2018-12599 In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file. Ubuntu Linux No fix yet Fix from $1,9502018-06-20 HIGH 8.8 CVE-2018-12600 In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file. Ubuntu Linux No fix yet Fix from $1,9502018-06-20 HIGH 8.8 CVE-2018-12293EPSS 11% The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prio… Ubuntu Linux 2.20.1 / 2.20.3+ Fix from $1,9502018-06-19 MEDIUM 6.5 CVE-2018-1152 libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image. Ubuntu Linux Patch available Fix from $1,6002018-06-18 CRITICAL 9.8 CVE-2018-11574 Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure,… Ubuntu Linux 2.4.9+ Fix from $2,3002018-06-14 HIGH 8.2 CVE-2018-11806 m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams. Ubuntu Linux Patch available Fix from $1,9502018-06-13 HIGH 7.5 CVE-2018-5177 A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow… Ubuntu Linux 60.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5181 If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local fi… Ubuntu Linux 60.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5182 If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local… Ubuntu Linux 60.0+ Fix from $1,9502018-06-11 MEDIUM 6.1 CVE-2018-5175 A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website c… Ubuntu Linux 60.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2018-5176 The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains maliciou… Ubuntu Linux 60.0+ Fix from $1,6002018-06-11 HIGH 8.1 CVE-2018-5163 If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data re… Ubuntu Linux 60.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5160 WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC en… Ubuntu Linux 60.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5166 WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access … Ubuntu Linux 60.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2018-5169 If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a… Ubuntu Linux 60.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5173 The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be use… Ubuntu Linux 60.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2018-5136 A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vu… Ubuntu Linux 59.0+ Fix from $1,9502018-06-11 HIGH 8.8 CVE-2018-5125 Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with… Ubuntu Linux 52.7.0 / 59.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2018-5089 Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with… Ubuntu Linux 52.6.0+ Fix from $2,3002018-06-11 MEDIUM 6.5 CVE-2018-10360 The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and applic… Ubuntu Linux Patch available Fix from $1,6002018-06-11 HIGH 8.8 CVE-2018-12085 Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-114… Ubuntu Linux Patch available Fix from $1,9502018-06-09 HIGH 7.5 CVE-2018-12015EPSS 7% In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary… Ubuntu Linux 10.14.4+ Fix from $1,9502018-06-07 HIGH 8.8 CVE-2018-11683 Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-114… Ubuntu Linux Mitigation only Fix from $1,9502018-06-04 HIGH 8.8 CVE-2018-11684 Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c. Ubuntu Linux Mitigation only Fix from $1,9502018-06-04 HIGH 8.8 CVE-2018-11685 Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c. Ubuntu Linux Mitigation only Fix from $1,9502018-06-04 MEDIUM 6.5 CVE-2018-11655 In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows atta… Ubuntu Linux No fix yet Fix from $1,6002018-06-01 MEDIUM 6.5 CVE-2018-11656 In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cau… Ubuntu Linux No fix yet Fix from $1,6002018-06-01 HIGH 8.8 CVE-2018-11625 In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file. Ubuntu Linux Patch available Fix from $1,9502018-05-31