Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux MEDIUM 6.5
CVE-2012-6123

Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

Fix: 4.8.0+
Fix from $1,600 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2013-1910

yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Tro…

Mitigation only
Fix from $2,300 2019-10-31
Debian Linux MEDIUM 6.5
CVE-2010-2490

Mumble: murmur-server has DoS due to malformed client query

Patch available
Fix from $1,600 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2010-0748

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr a…

Fix: 1.92+
Fix from $2,300 2019-10-30
Debian Linux MEDIUM 5.5
CVE-2010-3373

paxtest handles temporary files insecurely

No fix yet
Fix from $1,600 2019-10-29
Debian Linux HIGH 8.8
CVE-2019-17346

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatib…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux HIGH 7.8
CVE-2019-17347

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can mani…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux MEDIUM 6.5
CVE-2019-17348

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an incompatibility between Proce…

Fix: after 4.11.2
Fix from $1,600 2019-10-08
Debian Linux HIGH 8.8
CVE-2019-11071

SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishand…

Fix: 3.1.10 / 3.2.4+
Fix from $1,950 2019-04-10
Debian Linux MEDIUM 5.5
CVE-2019-1788

A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior c…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Debian Linux MEDIUM 5.5
CVE-2019-1787

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could all…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Debian Linux HIGH 7.5
CVE-2018-20743

murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote att…

Fix: after 1.2.19
Fix from $1,950 2019-01-25
Debian Linux MEDIUM 6.5
CVE-2018-20662

In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of…

Patch available
Fix from $1,600 2019-01-03
Debian Linux MEDIUM 5.5
CVE-2018-19478

In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

Fix: 9.26+
Fix from $1,600 2019-01-02
Debian Linux MEDIUM 6.5
CVE-2018-20189

In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is…

Patch available
Fix from $1,600 2018-12-17
Debian Linux MEDIUM 6.5
CVE-2018-19967

An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen …

Fix: after 4.11.1
Fix from $1,600 2018-12-08
Debian Linux HIGH 8.8
CVE-2018-19788EPSS 11%

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

Patch available
Fix from $1,950 2018-12-03
Debian Linux HIGH 7.5
CVE-2018-16472

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inhe…

Fix: after 1.0.1
Fix from $1,950 2018-11-06
Debian Linux MEDIUM 6.5
CVE-2018-14661

It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vuln…

Mitigation only
Fix from $1,600 2018-10-31
Debian Linux HIGH 7.5
CVE-2018-18541

In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker…

Fix: 0.6.5+
Fix from $1,950 2018-10-20
Debian Linux HIGH 7.8
CVE-2015-9268

Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechani…

Fix: 2.49+
Fix from $1,950 2018-10-01
Debian Linux MEDIUM 6.5
CVE-2018-16587

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to a…

Fix: 4.0.32 / 5.0.30+
Fix from $1,600 2018-09-28
Debian Linux MEDIUM 5.9
CVE-2016-7073

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middl…

Fix: 3.4.11 / 3.7.4+
Fix from $1,600 2018-09-11
Debian Linux MEDIUM 5.9
CVE-2016-7074

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middl…

Fix: 3.4.11 / 4.0.2+
Fix from $1,600 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7068EPSS 7%

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacke…

Fix: 3.4.11 / 3.7.4+
Fix from $1,950 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7072EPSS 6%

An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of ser…

Fix: 3.4.11 / 4.0.2+
Fix from $1,950 2018-09-10
Debian Linux HIGH 8.8
CVE-2018-10929

A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files an…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.1
CVE-2018-10927

A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and exec…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.8
CVE-2018-10858

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use th…

Fix: 4.6.16 / 4.7.9+
Fix from $1,950 2018-08-22
Debian Linux HIGH 8.8
CVE-2018-10873

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check…

Patch available
Fix from $1,950 2018-08-17