Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2018-14767EPSS 29% In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an… Debian Linux 5.0.7 / 5.1.4+ Fix from $2,3002018-07-31 HIGH 7.5 CVE-2016-9578 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send … Debian Linux 0.13.90+ Fix from $1,9502018-07-27 HIGH 8.8 CVE-2016-9577 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th… Debian Linux 0.13.90+ Fix from $1,9502018-07-27 CRITICAL 9.8 CVE-2018-14349 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message. Debian Linux 1.10.1 / 20180716+ Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-14361 An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data. Debian Linux 20180716+ Fix from $2,3002018-07-17 MEDIUM 6.5 CVE-2018-14055 ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inje… Debian Linux after 1.7.0 Fix from $1,6002018-07-15 MEDIUM 6.5 CVE-2018-10888 A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read whil… Debian Linux 0.27.3+ Fix from $1,6002018-07-10 HIGH 7.5 CVE-2017-2669 Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sen… Debian Linux after 2.2.28 Fix from $1,9502018-06-21 HIGH 8.8 CVE-2018-12565 An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote … Debian Linux after 2018.4 Fix from $1,9502018-06-19 MEDIUM 6.5 CVE-2018-12564 An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that wil… Debian Linux 2018.5.post1+ Fix from $1,6002018-06-19 MEDIUM 6.5 CVE-2018-12458 An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violati… Debian Linux Patch available Fix from $1,6002018-06-15 HIGH 8.8 CVE-2018-5130 When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. T… Debian Linux 52.7.0 / 59.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7825 Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for do… Debian Linux 52.4.0 / 56.0+ Fix from $1,6002018-06-11 HIGH 8.1 CVE-2017-7807 A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed… Debian Linux 52.3.0 / 55.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7791 On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page naviga… Debian Linux 52.3.0 / 55.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-5383 URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing… Debian Linux 45.7.0 / 51.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7653 The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that… Debian Linux after 1.4.15 Fix from $1,6002018-06-05 MEDIUM 5.3 CVE-2018-10995 SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields). Debian Linux after 17.02.10.1 Fix from $1,6002018-05-30 MEDIUM 5.5 CVE-2018-1000040 In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service … Debian Linux after 1.12.0 Fix from $1,6002018-05-24 MEDIUM 5.5 CVE-2018-1000037 In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) vi… Debian Linux after 1.12.0 Fix from $1,6002018-05-24 MEDIUM 5.4 CVE-2017-0366 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration. Debian Linux 1.27.2 / 1.28.1+ Fix from $1,6002018-04-13 MEDIUM 5.3 CVE-2017-0368 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages. Debian Linux 1.27.2 / 1.28.1+ Fix from $1,6002018-04-13 MEDIUM 5.3 CVE-2017-0370 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link par… Debian Linux 1.27.2 / 1.28.1+ Fix from $1,6002018-04-13 HIGH 7.5 CVE-2018-1086 pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th… Debian Linux Mitigation only Fix from $1,9502018-04-12 HIGH 8.8 CVE-2018-9846 In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled … Debian Linux after 1.3.5 Fix from $1,9502018-04-07 MEDIUM 5.3 CVE-2018-1000077 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a… Debian Linux after 2.5.0 Fix from $1,6002018-03-13 HIGH 8.6 CVE-2017-18123 The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download… Debian Linux after 2017-02-19e Fix from $1,9502018-02-03 MEDIUM 5.3 CVE-2011-2902 zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, wh… Debian Linux 3.02-19+ Fix from $1,6002018-01-30 HIGH 8.8 CVE-2018-6360 mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO element… Debian Linux after 0.28.0 Fix from $1,9502018-01-28 CRITICAL 9.8 CVE-2017-12176 xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server t… Debian Linux 1.19.5+ Fix from $2,3002018-01-24