Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.8
CVE-2019-9956EPSS 6%

In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a d…

No fix yet
Fix from $1,950 2019-03-24
Debian Linux HIGH 8.8
CVE-2019-9656

An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.c…

No fix yet
Fix from $1,950 2019-03-11
Debian Linux HIGH 7.8
CVE-2019-1999

In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privileg…

No fix yet
Fix from $1,950 2019-02-28
Debian Linux HIGH 7.8
CVE-2019-9210

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted m…

No fix yet
Fix from $1,950 2019-02-27
Debian Linux HIGH 8.8
CVE-2019-9200

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending…

No fix yet
Fix from $1,950 2019-02-26
Debian Linux HIGH 8.8
CVE-2019-8907

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or…

No fix yet
Fix from $1,950 2019-02-18
Debian Linux MEDIUM 5.0
CVE-2019-8354

An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When t…

Mitigation only
Fix from $1,600 2019-02-15
Debian Linux MEDIUM 5.5
CVE-2019-7665

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can…

No fix yet
Fix from $1,600 2019-02-09
Debian Linux CRITICAL 9.8
CVE-2019-7653

The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowi…

No fix yet
Fix from $2,300 2019-02-09
Debian Linux CRITICAL 9.8
CVE-2019-3463

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to …

Mitigation only
Fix from $2,300 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2019-3464

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restri…

Mitigation only
Fix from $2,300 2019-02-06
Debian Linux HIGH 7.8
CVE-2019-1000018

rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp p…

No fix yet
Fix from $1,950 2019-02-04
Tmpreaper HIGH 7.0
CVE-2019-3461

Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mo…

Mitigation only
Fix from $1,950 2019-02-04
Debian Linux MEDIUM 5.3
CVE-2017-3138EPSS 6%

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel…

Mitigation only
Fix from $1,600 2019-01-16
Debian Linux CRITICAL 9.8
CVE-2019-6256

A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer cr…

No fix yet
Fix from $2,300 2019-01-14
Debian Linux MEDIUM 6.5
CVE-2018-20622

JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.

Mitigation only
Fix from $1,600 2018-12-31
Debian Linux MEDIUM 6.5
CVE-2018-20570

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

No fix yet
Fix from $1,600 2018-12-28
Debian Linux HIGH 7.8
CVE-2018-20196

There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder…

No fix yet
Fix from $1,950 2018-12-18
Debian Linux MEDIUM 5.4
CVE-2018-18245

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plu…

No fix yet
Fix from $1,600 2018-12-17
Debian Linux HIGH 8.8
CVE-2018-20004

An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a do…

No fix yet
Fix from $1,950 2018-12-10
Debian Linux CRITICAL 9.1
CVE-2018-19857

The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies…

No fix yet
Fix from $2,300 2018-12-05
Debian Linux MEDIUM 5.5
CVE-2018-19777

In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.

No fix yet
Fix from $1,600 2018-11-30
Debian Linux MEDIUM 6.5
CVE-2018-19758

There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Debian Linux MEDIUM 6.5
CVE-2018-19661

An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of servic…

No fix yet
Fix from $1,600 2018-11-29
Debian Linux HIGH 8.8
CVE-2018-19540

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.1…

No fix yet
Fix from $1,950 2018-11-26
Debian Linux MEDIUM 6.5
CVE-2018-19539

An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a…

No fix yet
Fix from $1,600 2018-11-26
Debian Linux MEDIUM 6.5
CVE-2018-19210

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service a…

No fix yet
Fix from $1,600 2018-11-12
Debian Linux MEDIUM 6.5
CVE-2018-18897

An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.

No fix yet
Fix from $1,600 2018-11-02
Debian Linux MEDIUM 6.5
CVE-2018-14661

It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vuln…

Mitigation only
Fix from $1,600 2018-10-31
Crossroads HIGH 7.8
CVE-2018-18654

Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in …

Mitigation only
Fix from $1,950 2018-10-26