Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Debian Linux MEDIUM 5.3
CVE-2019-10247EPSS 6%

In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combinati…

Fix: after 3.1.3
Fix from $1,600 2019-04-22
Debian Linux MEDIUM 5.2
CVE-2019-3811

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the…

Fix: 2.1+
Fix from $1,600 2019-01-15
Debian Linux MEDIUM 6.5
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker …

Fix: 4.8.4+
Fix from $1,600 2018-12-11
Debian Linux HIGH 7.8
CVE-2018-19962

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU m…

Fix: after 4.11.1
Fix from $1,950 2018-12-08
Debian Linux MEDIUM 6.3
CVE-2018-18073

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack…

Patch available
Fix from $1,600 2018-10-15
Debian Linux HIGH 7.5
CVE-2018-16948

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables …

Fix: 1.6.23 / 1.8.2+
Fix from $1,950 2018-09-12
Debian Linux HIGH 8.1
CVE-2018-10927

A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and exec…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux MEDIUM 5.3
CVE-2018-15599

The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validi…

Fix: after 2018.76
Fix from $1,600 2018-08-21
Debian Linux MEDIUM 5.5
CVE-2018-15594

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectr…

Fix: 4.18.1+
Fix from $1,600 2018-08-20
Debian Linux HIGH 8.1
CVE-2018-14348

libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

Fix: after 0.41
Fix from $1,950 2018-08-14
Debian Linux MEDIUM 5.3
CVE-2018-14432

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may by…

Fix: 11.0.4+
Fix from $1,600 2018-07-31
Debian Linux HIGH 7.0
CVE-2017-2624

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the co…

Fix: after 1.19.4
Fix from $1,950 2018-07-27
Debian Linux HIGH 7.5
CVE-2018-10857

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex reposi…

Mitigation only
Fix from $1,950 2018-07-16
Debian Linux HIGH 7.5
CVE-2018-10859

git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypti…

Mitigation only
Fix from $1,950 2018-07-16
Debian Linux CRITICAL 9.9
CVE-2018-12892

An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…

Fix: after 4.10.1
Fix from $2,300 2018-07-02
Debian Linux HIGH 7.5
CVE-2018-10852

The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can s…

Fix: 1.16.3+
Fix from $1,950 2018-06-26
Debian Linux MEDIUM 5.3
CVE-2018-12227

An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert bef…

Fix: 13.21.1 / 14.7.7+
Fix from $1,600 2018-06-12
Debian Linux MEDIUM 5.9
CVE-2018-5131

Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache hea…

Fix: 52.7.0 / 59.0+
Fix from $1,600 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-7843

When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB …

Fix: 52.5.2 / 57.0.1+
Fix from $1,950 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-7787

Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top …

Fix: 55.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 6.5
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted us…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-5408

Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potenti…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-5378

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash…

Fix: 45.7.0 / 51.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.6
CVE-2018-10472

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live i…

Fix: after 4.10.1
Fix from $1,600 2018-04-27
Debian Linux HIGH 7.8
CVE-2017-0361

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.

Fix: 1.27.2 / 1.28.1+
Fix from $1,950 2018-04-13
Debian Linux HIGH 7.5
CVE-2018-1086

pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th…

Mitigation only
Fix from $1,950 2018-04-12
Debian Linux HIGH 7.1
CVE-2017-14461EPSS 17%

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive info…

Patch available
Fix from $1,950 2018-03-02
Debian Linux CRITICAL 9.1
CVE-2018-7556

LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installatio…

Fix: 2.6.7 / 2.73.1+
Fix from $2,300 2018-02-28
Debian Linux CRITICAL 9.1
CVE-2018-6596

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al…

Fix: 1.2.1+
Fix from $2,300 2018-02-03
Debian Linux HIGH 8.8
CVE-2017-17476

Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remo…

Fix: 4.0.28 / 5.0.26+
Fix from $1,950 2017-12-20