Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux CRITICAL 9.8
CVE-2018-14767EPSS 29%

In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…

Fix: 5.0.7 / 5.1.4+
Fix from $2,300 2018-07-31
Debian Linux HIGH 7.5
CVE-2016-9578

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send …

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Debian Linux HIGH 8.8
CVE-2016-9577

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th…

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Debian Linux CRITICAL 9.8
CVE-2018-14349

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14361

An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.

Fix: 20180716+
Fix from $2,300 2018-07-17
Debian Linux MEDIUM 6.5
CVE-2018-14055

ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inje…

Fix: after 1.7.0
Fix from $1,600 2018-07-15
Debian Linux MEDIUM 6.5
CVE-2018-10888

A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read whil…

Fix: 0.27.3+
Fix from $1,600 2018-07-10
Debian Linux HIGH 7.5
CVE-2017-2669

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sen…

Fix: after 2.2.28
Fix from $1,950 2018-06-21
Debian Linux HIGH 8.8
CVE-2018-12565

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote …

Fix: after 2018.4
Fix from $1,950 2018-06-19
Debian Linux MEDIUM 6.5
CVE-2018-12564

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that wil…

Fix: 2018.5.post1+
Fix from $1,600 2018-06-19
Debian Linux MEDIUM 6.5
CVE-2018-12458

An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violati…

Patch available
Fix from $1,600 2018-06-15
Debian Linux HIGH 8.8
CVE-2018-5130

When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. T…

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-7825

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for do…

Fix: 52.4.0 / 56.0+
Fix from $1,600 2018-06-11
Debian Linux HIGH 8.1
CVE-2017-7807

A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-7791

On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page naviga…

Fix: 52.3.0 / 55.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-5383

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing…

Fix: 45.7.0 / 51.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-7653

The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that…

Fix: after 1.4.15
Fix from $1,600 2018-06-05
Debian Linux MEDIUM 5.3
CVE-2018-10995

SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).

Fix: after 17.02.10.1
Fix from $1,600 2018-05-30
Debian Linux MEDIUM 5.5
CVE-2018-1000040

In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service …

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Debian Linux MEDIUM 5.5
CVE-2018-1000037

In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) vi…

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Debian Linux MEDIUM 5.4
CVE-2017-0366

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2017-0368

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2017-0370

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link par…

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux HIGH 7.5
CVE-2018-1086

pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th…

Mitigation only
Fix from $1,950 2018-04-12
Debian Linux HIGH 8.8
CVE-2018-9846

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled …

Fix: after 1.3.5
Fix from $1,950 2018-04-07
Debian Linux MEDIUM 5.3
CVE-2018-1000077

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,600 2018-03-13
Debian Linux HIGH 8.6
CVE-2017-18123

The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download…

Fix: after 2017-02-19e
Fix from $1,950 2018-02-03
Debian Linux MEDIUM 5.3
CVE-2011-2902

zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, wh…

Fix: 3.02-19+
Fix from $1,600 2018-01-30
Debian Linux HIGH 8.8
CVE-2018-6360

mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO element…

Fix: after 0.28.0
Fix from $1,950 2018-01-28
Debian Linux CRITICAL 9.8
CVE-2017-12176

xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server t…

Fix: 1.19.5+
Fix from $2,300 2018-01-24