Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2017-12178 xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash o… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12180 xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or pos… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12181 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possib… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12182 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possib… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12183 xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly ex… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12184 xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly … Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12185 xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or p… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12186 xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibl… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-12187 xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly ex… Debian Linux 1.19.5+ Fix from $2,3002018-01-24 MEDIUM 5.3 CVE-2017-15105 A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be u… Debian Linux 1.6.8+ Fix from $1,6002018-01-23 MEDIUM 6.5 CVE-2017-12197 It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di… Debian Linux after 1.8 Fix from $1,6002018-01-18 HIGH 7.5 CVE-2017-13194 A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android … Debian Linux Patch available Fix from $1,9502018-01-12 HIGH 7.5 CVE-2017-17846 An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily… Debian Linux 1.9.9+ Fix from $1,9502017-12-27 CRITICAL 10.0 CVE-2017-16845 hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. Debian Linux after 2.11.2 Fix from $2,3002017-11-17 HIGH 7.5 CVE-2017-8814 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a … Debian Linux after 1.27.3 Fix from $1,9502017-11-15 HIGH 7.5 CVE-2017-8815 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rul… Debian Linux after 1.27.3 Fix from $1,9502017-11-15 MEDIUM 6.1 CVE-2017-8811 The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling… Debian Linux after 1.27.3 Fix from $1,6002017-11-15 HIGH 7.5 CVE-2017-16227EPSS 19% The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT… Debian Linux after 1.2.1 Fix from $1,9502017-10-29 HIGH 7.8 CVE-2013-6049 apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors. Debian Linux Mitigation only Fix from $1,9502017-10-20 MEDIUM 6.5 CVE-2017-14604 GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .de… Debian Linux 3.23.90+ Fix from $1,6002017-09-20 HIGH 8.8 CVE-2017-14169 In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, whi… Debian Linux Patch available Fix from $1,9502017-09-07 HIGH 7.5 CVE-2017-12874 The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature valid… Debian Linux Patch available Fix from $1,9502017-09-01 HIGH 7.5 CVE-2017-12869 The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentica… Debian Linux after 1.14.13 Fix from $1,9502017-09-01 HIGH 7.5 CVE-2017-0900EPSS 8% RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clie… Debian Linux after 2.6.12 Fix from $1,9502017-08-31 HIGH 7.5 CVE-2017-0901EPSS 29% RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th… Debian Linux Patch available Fix from $1,9502017-08-31 MEDIUM 6.5 CVE-2017-13145 In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, lead… Debian Linux after 6.9.8-7 Fix from $1,6002017-08-23 HIGH 7.5 CVE-2015-7704EPSS 11% The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" … Debian Linux Mitigation only Fix from $1,9502017-08-07 MEDIUM 6.5 CVE-2015-7855EPSS 31% The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertio… Debian Linux 4.2.8 / 4.3.77+ Fix from $1,6002017-08-07 MEDIUM 5.9 CVE-2015-7852EPSS 12% ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response pa… Debian Linux Patch available Fix from $1,6002017-08-07 MEDIUM 5.9 CVE-2017-11104 Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key na… Debian Linux after 2.4.4 Fix from $1,6002017-07-08