Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Debian Linux HIGH 7.3
CVE-2024-33601

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xreallo…

Fix: 2.40+
Fix from $1,950 2024-05-06
Debian Linux HIGH 7.8
CVE-2023-52621

In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers These thre…

Fix: 5.10.237 / 5.15.181+
Fix from $1,950 2024-03-26
Debian Linux HIGH 7.5
CVE-2023-40462

The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in…

Fix: after 4.16.0
Fix from $1,950 2023-12-04
Debian Linux MEDIUM 6.5
CVE-2022-37051

An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lack…

Patch available
Fix from $1,600 2023-08-22
Debian Linux HIGH 7.5
CVE-2023-39534

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, …

Fix: 2.6.5 / 2.9.2+
Fix from $1,950 2023-08-11
Debian Linux HIGH 7.5
CVE-2023-39949

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5…

Fix: 2.6.5+
Fix from $1,950 2023-08-11
Debian Linux MEDIUM 6.5
CVE-2022-2520

A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when readi…

Patch available
Fix from $1,600 2022-08-31
Debian Linux MEDIUM 6.5
CVE-2021-46784

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing l…

Fix: 5.6+
Fix from $1,600 2022-07-17
Debian Linux MEDIUM 6.5
CVE-2022-0865

Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff …

Patch available
Fix from $1,600 2022-03-10
Debian Linux HIGH 7.8
CVE-2021-36409

There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to ca…

No fix yet
Fix from $1,950 2022-01-10
Debian Linux HIGH 7.5
CVE-2021-38291

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

Fix: 4.1.7 / 4.2.5+
Fix from $1,950 2021-08-12
Debian Linux HIGH 7.5
CVE-2020-25709

A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an …

Fix: 2.4.56 / 10.14.6+
Fix from $1,950 2021-05-18
Debian Linux HIGH 7.5
CVE-2021-25215EPSS 11%

In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, …

Fix: 9.11.31 / 9.16.15+
Fix from $1,950 2021-04-29
Debian Linux MEDIUM 6.5
CVE-2021-25214EPSS 6%

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported…

Fix: 1.0.1.1 / 9.11.31+
Fix from $1,600 2021-04-29
Debian Linux HIGH 7.5
CVE-2019-25036

Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Althou…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux HIGH 7.5
CVE-2019-25037

Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this i…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux HIGH 7.5
CVE-2019-25041

Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Alt…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux HIGH 7.5
CVE-2021-20272

A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-27212EPSS 64%

In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a craft…

Fix: after 2.4.57
Fix from $1,950 2021-02-14
Debian Linux HIGH 7.5
CVE-2021-3326

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding,…

Fix: after 11.60.3
Fix from $1,950 2021-01-27
Debian Linux HIGH 7.5
CVE-2020-36230EPSS 12%

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, result…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36222EPSS 78%

A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of servic…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux MEDIUM 6.5
CVE-2020-27617

eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data…

Patch available
Fix from $1,600 2020-11-06
Debian Linux HIGH 7.5
CVE-2020-27638

receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

Fix: 21.0+
Fix from $1,950 2020-10-22
Debian Linux HIGH 7.5
CVE-2020-6097

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequenc…

No fix yet
Fix from $1,950 2020-09-10
Debian Linux MEDIUM 5.9
CVE-2020-8617EPSS 93%

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfu…

Fix: after 9.17.1
Fix from $1,600 2020-05-19
Debian Linux HIGH 7.5
CVE-2020-11653

An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a …

Fix: 6.0.6 / 6.2.3+
Fix from $1,950 2020-04-08
Debian Linux HIGH 7.5
CVE-2011-3596EPSS 11%

Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.

Fix: 1.0.4.1+
Fix from $1,950 2019-11-26
Debian Linux MEDIUM 6.5
CVE-2012-5521

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

Mitigation only
Fix from $1,600 2019-11-25
Debian Linux HIGH 7.5
CVE-2019-15892EPSS 6%

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to tr…

Fix: 6.0.4 / 6.2.1+
Fix from $1,950 2019-09-03