Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2018-9234 GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently… Ubuntu Linux Mitigation only Fix from $1,9502018-04-04 MEDIUM 6.5 CVE-2018-9133 ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of… Ubuntu Linux No fix yet Fix from $1,6002018-03-30 HIGH 7.0 CVE-2018-8885 screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intend… Screen Resolution Extra Mitigation only Fix from $1,9502018-03-28 HIGH 7.8 CVE-2018-1083 Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a sp… Ubuntu Linux after 5.4.1 Fix from $1,9502018-03-28 MEDIUM 5.5 CVE-2018-0202 clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con… Ubuntu Linux after 0.99.3 Fix from $1,6002018-03-27 MEDIUM 6.5 CVE-2017-18251 An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote … Ubuntu Linux Patch available Fix from $1,6002018-03-27 MEDIUM 6.5 CVE-2017-18252 An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (as… Ubuntu Linux Patch available Fix from $1,6002018-03-27 MEDIUM 6.5 CVE-2017-18254 An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote… Ubuntu Linux Patch available Fix from $1,6002018-03-27 HIGH 8.8 CVE-2018-8960 The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer … Ubuntu Linux No fix yet Fix from $1,9502018-03-23 HIGH 7.3 CVE-2018-8881 Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string. Ubuntu Linux Mitigation only Fix from $1,9502018-03-20 HIGH 7.5 CVE-2018-1000135 GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DN… Ubuntu Linux after 1.10.2 Fix from $1,9502018-03-20 HIGH 8.8 CVE-2018-8804 WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCore/memory.c double free and a… Ubuntu Linux Mitigation only Fix from $1,9502018-03-20 HIGH 8.8 CVE-2018-1057EPSS 10% On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowi… Ubuntu Linux 4.5.16 / 4.6.14+ Fix from $1,9502018-03-13 HIGH 7.8 CVE-2018-1000097 Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, f… Ubuntu Linux Mitigation only Fix from $1,9502018-03-13 MEDIUM 6.5 CVE-2016-9600 JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially craf… Ubuntu Linux 2.0.10+ Fix from $1,6002018-03-12 MEDIUM 5.3 CVE-2018-7536 An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely… Ubuntu Linux 1.8.19 / 1.11.11+ Fix from $1,6002018-03-09 MEDIUM 5.3 CVE-2018-7537 An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() … Ubuntu Linux 1.8.19 / 1.11.11+ Fix from $1,6002018-03-09 HIGH 7.5 CVE-2018-7182EPSS 29% The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted… Ubuntu Linux Patch available Fix from $1,9502018-03-06 HIGH 7.5 CVE-2018-7184EPSS 9% ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of se… Ubuntu Linux No fix yet Fix from $1,9502018-03-06 HIGH 7.5 CVE-2018-7185EPSS 9% The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet … Ubuntu Linux 1.1.6-6931-3 / 2.2.3-1505+ Fix from $1,9502018-03-06 MEDIUM 5.5 CVE-2018-7728 An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-… Ubuntu Linux after 2.4.4 Fix from $1,6002018-03-06 MEDIUM 5.5 CVE-2018-7729 An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScript_MetaHandler::ParsePSFile() function in XMP… Ubuntu Linux after 2.4.4 Fix from $1,6002018-03-06 MEDIUM 5.5 CVE-2018-7731 An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a bitstream has a NULL value, … Ubuntu Linux after 2.4.4 Fix from $1,6002018-03-06 HIGH 7.8 CVE-2018-1000100 GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap c… Ubuntu Linux after 0.7.1 Fix from $1,9502018-03-06 MEDIUM 6.5 CVE-2018-7725 An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability c… Ubuntu Linux No fix yet Fix from $1,6002018-03-06 MEDIUM 6.5 CVE-2018-7726 An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverag… Ubuntu Linux No fix yet Fix from $1,6002018-03-06 HIGH 7.5 CVE-2018-1000115EPSS 88% Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support … Ubuntu Linux Patch available Fix from $1,9502018-03-05 CRITICAL 9.8 CVE-2017-18211 In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-loo… Ubuntu Linux Patch available Fix from $2,3002018-03-01 HIGH 8.8 CVE-2017-18209 In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memo… Ubuntu Linux Patch available Fix from $1,9502018-03-01 CRITICAL 9.8 CVE-2014-10071 In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax. Ubuntu Linux 5.0.7+ Fix from $2,3002018-02-27