Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux CRITICAL 9.8
CVE-2017-12178

xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash o…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12180

xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or pos…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12181

xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possib…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12182

xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possib…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12183

xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly ex…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12184

xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly …

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12185

xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or p…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12186

xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibl…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12187

xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly ex…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux MEDIUM 5.3
CVE-2017-15105

A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be u…

Fix: 1.6.8+
Fix from $1,600 2018-01-23
Debian Linux MEDIUM 6.5
CVE-2017-12197

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di…

Fix: after 1.8
Fix from $1,600 2018-01-18
Debian Linux HIGH 7.5
CVE-2017-13194

A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android …

Patch available
Fix from $1,950 2018-01-12
Debian Linux HIGH 7.5
CVE-2017-17846

An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux CRITICAL 10.0
CVE-2017-16845

hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.

Fix: after 2.11.2
Fix from $2,300 2017-11-17
Debian Linux HIGH 7.5
CVE-2017-8814

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a …

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-8815

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rul…

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Debian Linux MEDIUM 6.1
CVE-2017-8811

The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling…

Fix: after 1.27.3
Fix from $1,600 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-16227EPSS 19%

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT…

Fix: after 1.2.1
Fix from $1,950 2017-10-29
Debian Linux HIGH 7.8
CVE-2013-6049

apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors.

Mitigation only
Fix from $1,950 2017-10-20
Debian Linux MEDIUM 6.5
CVE-2017-14604

GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .de…

Fix: 3.23.90+
Fix from $1,600 2017-09-20
Debian Linux HIGH 8.8
CVE-2017-14169

In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, whi…

Patch available
Fix from $1,950 2017-09-07
Debian Linux HIGH 7.5
CVE-2017-12874

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature valid…

Patch available
Fix from $1,950 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-12869

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentica…

Fix: after 1.14.13
Fix from $1,950 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-0900EPSS 8%

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clie…

Fix: after 2.6.12
Fix from $1,950 2017-08-31
Debian Linux HIGH 7.5
CVE-2017-0901EPSS 29%

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th…

Patch available
Fix from $1,950 2017-08-31
Debian Linux MEDIUM 6.5
CVE-2017-13145

In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, lead…

Fix: after 6.9.8-7
Fix from $1,600 2017-08-23
Debian Linux HIGH 7.5
CVE-2015-7704EPSS 11%

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" …

Mitigation only
Fix from $1,950 2017-08-07
Debian Linux MEDIUM 6.5
CVE-2015-7855EPSS 31%

The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertio…

Fix: 4.2.8 / 4.3.77+
Fix from $1,600 2017-08-07
Debian Linux MEDIUM 5.9
CVE-2015-7852EPSS 12%

ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response pa…

Patch available
Fix from $1,600 2017-08-07
Debian Linux MEDIUM 5.9
CVE-2017-11104

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key na…

Fix: after 2.4.4
Fix from $1,600 2017-07-08