Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux HIGH 7.8
CVE-2021-36047

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execut…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 7.8
CVE-2021-36048

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execut…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 7.5
CVE-2021-31863

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine us…

Fix: 4.0.9 / 4.1.3+
Fix from $1,950 2021-04-28
Debian Linux MEDIUM 5.5
CVE-2020-10001

An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, …

Fix: 11.1.0+
Fix from $1,600 2021-04-02
Debian Linux HIGH 8.6
CVE-2020-25097EPSS 8%

An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Req…

Fix: 4.14 / 5.0.5+
Fix from $1,950 2021-03-19
Debian Linux HIGH 7.5
CVE-2021-20273

A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.4
CVE-2021-20247

A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or…

Fix: 1.3.5 / 1.4.1+
Fix from $1,950 2021-02-23
Debian Linux HIGH 7.8
CVE-2020-27844

A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg dur…

Fix: 2.4.0+
Fix from $1,950 2021-01-05
Debian Linux HIGH 7.5
CVE-2020-25275

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain …

Fix: 2.3.13+
Fix from $1,950 2021-01-04
Debian Linux HIGH 7.5
CVE-2020-8184

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2020-06-19
Apt MEDIUM 5.5
CVE-2020-3810

Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafte…

Fix: 2.1.2+
Fix from $1,600 2020-05-15
Debian Linux HIGH 7.5
CVE-2015-5230EPSS 9%

The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of se…

Fix: 3.4.6+
Fix from $1,950 2020-01-15
Debian Linux HIGH 7.5
CVE-2012-6111

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

Mitigation only
Fix from $1,950 2019-12-20
Debian Linux HIGH 7.8
CVE-2012-3409

ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

Fix: 99+
Fix from $1,950 2019-12-20
Debian Linux HIGH 7.3
CVE-2013-4245

Orca has arbitrary code execution due to insecure Python module load

Mitigation only
Fix from $1,950 2019-12-11
Debian Linux HIGH 8.1
CVE-2012-2248

An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.

Mitigation only
Fix from $1,950 2019-11-27
Debian Linux CRITICAL 9.8
CVE-2011-4120

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured…

Fix: 2.10+
Fix from $2,300 2019-11-26
Debian Linux HIGH 7.5
CVE-2014-1936

rc before 1.7.1-5 insecurely creates temporary files.

Fix: 1.7.1-5+
Fix from $1,950 2019-11-21
Debian Linux MEDIUM 5.3
CVE-2014-1935

9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.

No fix yet
Fix from $1,600 2019-11-21
Debian Linux HIGH 7.5
CVE-2012-2350

pam_shield before 0.9.4: Default configuration does not perform protective action

Fix: 0.9.4+
Fix from $1,950 2019-11-21
Debian Linux HIGH 7.5
CVE-2013-1816

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially craf…

Fix: 1.19.4 / 1.20.3+
Fix from $1,950 2019-11-20
Debian Linux HIGH 7.5
CVE-2011-0529

Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.

Fix: 0.12.5+
Fix from $1,950 2019-11-20
Debian Linux CRITICAL 9.8
CVE-2011-1028

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_s…

Fix: 3.0.7+
Fix from $2,300 2019-11-20
Debian Linux CRITICAL 9.8
CVE-2011-0703

In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 ses…

Fix: 0.0.3+
Fix from $2,300 2019-11-15
Debian Linux MEDIUM 6.5
CVE-2018-12207

Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to …

Fix: after 15.0.1
Fix from $1,600 2019-11-14
Debian Linux MEDIUM 6.5
CVE-2010-3439

It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download co…

No fix yet
Fix from $1,600 2019-11-12
Debian Linux HIGH 7.4
CVE-2012-0051

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

No fix yet
Fix from $1,950 2019-11-07
Shadow HIGH 7.8
CVE-2005-4890

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to…

Fix: after 4.1.5
Fix from $1,950 2019-11-04
Debian Linux HIGH 7.5
CVE-2013-2227EPSS 13%

GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

No fix yet
Fix from $1,950 2019-11-01
Debian Linux MEDIUM 5.5
CVE-2013-3718

evince is missing a check on number of pages which can lead to a segmentation fault

Patch available
Fix from $1,600 2019-11-01