Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2019-10247EPSS 6% In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combinati… Debian Linux after 3.1.3 Fix from $1,6002019-04-22 MEDIUM 5.2 CVE-2019-3811 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the… Debian Linux 2.1+ Fix from $1,6002019-01-15 MEDIUM 6.5 CVE-2018-19968 An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker … Debian Linux 4.8.4+ Fix from $1,6002018-12-11 HIGH 7.8 CVE-2018-19962 An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU m… Debian Linux after 4.11.1 Fix from $1,9502018-12-08 MEDIUM 6.3 CVE-2018-18073 Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack… Debian Linux Patch available Fix from $1,6002018-10-15 HIGH 7.5 CVE-2018-16948 An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables … Debian Linux 1.6.23 / 1.8.2+ Fix from $1,9502018-09-12 HIGH 8.1 CVE-2018-10927 A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and exec… Debian Linux 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 MEDIUM 5.3 CVE-2018-15599 The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validi… Debian Linux after 2018.76 Fix from $1,6002018-08-21 MEDIUM 5.5 CVE-2018-15594 arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectr… Debian Linux 4.18.1+ Fix from $1,6002018-08-20 HIGH 8.1 CVE-2018-14348 libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information. Debian Linux after 0.41 Fix from $1,9502018-08-14 MEDIUM 5.3 CVE-2018-14432 In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may by… Debian Linux 11.0.4+ Fix from $1,6002018-07-31 HIGH 7.0 CVE-2017-2624 It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the co… Debian Linux after 1.19.4 Fix from $1,9502018-07-27 HIGH 7.5 CVE-2018-10857 git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex reposi… Debian Linux Mitigation only Fix from $1,9502018-07-16 HIGH 7.5 CVE-2018-10859 git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypti… Debian Linux Mitigation only Fix from $1,9502018-07-16 CRITICAL 9.9 CVE-2018-12892 An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl… Debian Linux after 4.10.1 Fix from $2,3002018-07-02 HIGH 7.5 CVE-2018-10852 The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can s… Debian Linux 1.16.3+ Fix from $1,9502018-06-26 MEDIUM 5.3 CVE-2018-12227 An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert bef… Debian Linux 13.21.1 / 14.7.7+ Fix from $1,6002018-06-12 MEDIUM 5.9 CVE-2018-5131 Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache hea… Debian Linux 52.7.0 / 59.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-7843 When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB … Debian Linux 52.5.2 / 57.0.1+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7787 Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top … Debian Linux 55.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2017-5407 Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted us… Debian Linux 45.8.0 / 52.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-5408 Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potenti… Debian Linux 45.8.0 / 52.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-5378 Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash… Debian Linux 45.7.0 / 51.0+ Fix from $1,9502018-06-11 MEDIUM 5.6 CVE-2018-10472 An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live i… Debian Linux after 4.10.1 Fix from $1,6002018-04-27 HIGH 7.8 CVE-2017-0361 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext. Debian Linux 1.27.2 / 1.28.1+ Fix from $1,9502018-04-13 HIGH 7.5 CVE-2018-1086 pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th… Debian Linux Mitigation only Fix from $1,9502018-04-12 HIGH 7.1 CVE-2017-14461EPSS 17% A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive info… Debian Linux Patch available Fix from $1,9502018-03-02 CRITICAL 9.1 CVE-2018-7556 LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installatio… Debian Linux 2.6.7 / 2.73.1+ Fix from $2,3002018-02-28 CRITICAL 9.1 CVE-2018-6596 webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al… Debian Linux 1.2.1+ Fix from $2,3002018-02-03 HIGH 8.8 CVE-2017-17476 Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remo… Debian Linux 4.0.28 / 5.0.26+ Fix from $1,9502017-12-20