Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Debian Linux MEDIUM 6.5
CVE-2017-16854

In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a custo…

Fix: after 6.0.1
Fix from $1,600 2017-12-08
Debian Linux HIGH 7.5
CVE-2017-8810

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for fai…

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Debian Linux MEDIUM 6.5
CVE-2017-16353EPSS 14%

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil…

No fix yet
Fix from $1,600 2017-11-01
Debian Linux HIGH 7.5
CVE-2017-15576

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive info…

Fix: after 3.2.5
Fix from $1,950 2017-10-18
Debian Linux HIGH 7.5
CVE-2017-15577

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

Fix: after 3.2.5
Fix from $1,950 2017-10-18
Debian Linux MEDIUM 5.9
CVE-2017-12872

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote att…

Fix: after 1.14.11
Fix from $1,600 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-0379

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, rela…

Fix: after 1.8.0
Fix from $1,950 2017-08-29
Debian Linux HIGH 7.5
CVE-2017-9993EPSS 16%

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filenam…

Fix: 2.8.12 / 3.1.9+
Fix from $1,950 2017-06-28
Debian Linux MEDIUM 5.5
CVE-2017-9868

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic infor…

Fix: after 1.4.12
Fix from $1,600 2017-06-25
Debian Linux HIGH 7.8
CVE-2017-4966

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb…

Mitigation only
Fix from $1,950 2017-06-13
Debian Linux MEDIUM 5.5
CVE-2013-5653

The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted p…

Patch available
Fix from $1,600 2017-03-07
Debian Linux HIGH 7.5
CVE-2016-10002EPSS 7%

Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, an…

Patch available
Fix from $1,950 2017-01-27
Debian Linux MEDIUM 5.3
CVE-2016-6313

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 mak…

Fix: after 1.5.3
Fix from $1,600 2016-12-13
Debian Linux MEDIUM 6.0
CVE-2016-9103

The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory …

Fix: after 2.7.1
Fix from $1,600 2016-12-09
Debian Linux MEDIUM 6.5
CVE-2016-1698

The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not val…

Fix: after 51.0.2704.63
Fix from $1,600 2016-06-05
Debian Linux MEDIUM 6.5
CVE-2016-1687

The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Debian Linux HIGH 7.5
CVE-2016-2849

Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which migh…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2016-2055EPSS 18%

xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration director…

Patch available
Fix from $1,950 2016-04-13
Debian Linux MEDIUM 5.3
CVE-2016-3170

The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensi…

Patch available
Fix from $1,600 2016-04-12
Debian Linux MEDIUM 5.3
CVE-2015-8537

app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive info…

Fix: after 2.6.8
Fix from $1,600 2016-04-12
Debian Linux HIGH 8.1
CVE-2016-1526

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before…

Fix: after 38.5.1
Fix from $1,950 2016-02-13
Debian Linux MEDIUM 5.3
CVE-2015-5299EPSS 14%

The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before…

Fix: 4.1.22 / 4.2.7+
Fix from $1,600 2015-12-29
Debian Linux MEDIUM 5.0
CVE-2015-7762

rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowl…

Fix: after 1.6.14.1
Fix from $1,600 2015-11-06
Debian Linux MEDIUM 5.0
CVE-2015-1165

RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket…

Mitigation only
Fix from $1,600 2015-03-09
Debian Linux MEDIUM 5.0
CVE-2014-1829

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected requ…

Fix: after 2.2.1
Fix from $1,600 2014-10-15
Devotee MEDIUM 5.0
CVE-2012-2387

devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers…

Mitigation only
Fix from $1,600 2012-08-20
Debian Linux MEDIUM 5.0
CVE-2011-4360

MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or…

Fix: 1.17.1+
Fix from $1,600 2012-01-08
Libdbd Pg Perl MEDIUM 5.0
CVE-2009-1341

Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-depend…

Fix: after 1.4.9
Fix from $1,600 2009-04-30
Debian Linux HIGH 7.5
CVE-2008-4359

lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, w…

Fix: 1.4.20+
Fix from $1,950 2008-10-03
Debian Linux HIGH 7.5
CVE-2008-4360

mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filenam…

Fix: 1.4.20+
Fix from $1,950 2008-10-03