Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2016-10714
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
Ubuntu Linux
5.3+
CRITICAL 9.8
CVE-2017-18206
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
Ubuntu Linux
5.4+
CRITICAL 9.8
CVE-2018-7548
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
Ubuntu Linux
after 5.4.2
HIGH 7.5
CVE-2018-5381EPSS 30%
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capabili…
Ubuntu Linux
2.13.0+
CRITICAL 9.8
CVE-2018-7054
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE:…
Ubuntu Linux
1.0.7+
HIGH 7.5
CVE-2018-7052
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL p…
Ubuntu Linux
1.0.7+
HIGH 7.8
CVE-2018-6954
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of …
Ubuntu Linux
after 237
HIGH 7.5
CVE-2018-6951EPSS 8%
An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of…
Ubuntu Linux
after 2.7.6
MEDIUM 6.5
CVE-2018-6942
An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS …
Ubuntu Linux
after 2.9
MEDIUM 5.5
CVE-2017-10689
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a f…
Ubuntu Linux
1.10.10 / 5.3.4+
HIGH 7.8
CVE-2017-14177
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker…
Ubuntu Linux
after 2.20.7
HIGH 7.8
CVE-2017-14179
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an at…
Ubuntu Linux
2.13+
HIGH 7.8
CVE-2017-14180
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root whi…
Ubuntu Linux
after 2.20.7
MEDIUM 6.5
CVE-2018-6540
In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote atta…
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2018-6541
In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_…
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2018-6484
In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could l…
Ubuntu Linux
No fix yet
HIGH 7.8
CVE-2018-1000001EPSS 13%
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading …
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2018-6405
In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new …
Ubuntu Linux
6.9.9-35 / 7.0.7-23+
MEDIUM 6.5
CVE-2018-6381
In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a segmentation faul…
Ubuntu Linux
No fix yet
HIGH 7.5
CVE-2018-6196
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a neg…
Ubuntu Linux
after 0.5.3
HIGH 7.5
CVE-2018-6197
w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.
Ubuntu Linux
after 0.5.3
MEDIUM 6.5
CVE-2017-18027
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause…
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2017-18028
In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers …
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2017-18029
In ImageMagick 7.0.6-10 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to caus…
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2018-5357
ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2018-5358
ImageMagick 7.0.7-22 Q16 has memory leaks in the EncodeImageAttributes function in coders/json.c, as demonstrated by the ReadPSDLayersInternal functi…
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2017-18022
In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2018-5246
In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadPATTERNImage in coders/pattern.c.
Ubuntu Linux
No fix yet
MEDIUM 6.5
CVE-2018-5247
In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadRLAImage in coders/rla.c.
Ubuntu Linux
No fix yet
MEDIUM 5.6
CVE-2017-5715EPSS 74%
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an at…
Ubuntu Linux
Patch available