Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2018-18605

A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka …

No fix yet
Fix from $1,600 2018-10-23
Debian Linux MEDIUM 5.5
CVE-2018-18606

An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binu…

No fix yet
Fix from $1,600 2018-10-23
Debian Linux MEDIUM 5.5
CVE-2018-18607

An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2…

No fix yet
Fix from $1,600 2018-10-23
Debian Linux HIGH 8.8
CVE-2018-18557EPSS 15%

LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.…

No fix yet
Fix from $1,950 2018-10-22
Debian Linux CRITICAL 9.8
CVE-2018-4013EPSS 10%

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specia…

No fix yet
Fix from $2,300 2018-10-19
Debian Linux MEDIUM 6.5
CVE-2018-18088

OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c

No fix yet
Fix from $1,600 2018-10-09
Debian Linux CRITICAL 9.8
CVE-2018-17141EPSS 6%

HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit en…

No fix yet
Fix from $2,300 2018-09-21
Debian Linux MEDIUM 6.5
CVE-2018-17000

A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an a…

No fix yet
Fix from $1,600 2018-09-13
Debian Linux HIGH 8.8
CVE-2018-16981

stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.

No fix yet
Fix from $1,950 2018-09-12
Debian Linux HIGH 7.8
CVE-2018-16802

An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception …

Mitigation only
Fix from $1,950 2018-09-10
Debian Linux MEDIUM 6.1
CVE-2018-1000671

sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of th…

No fix yet
Fix from $1,600 2018-09-06
Debian Linux CRITICAL 9.8
CVE-2018-16402

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecif…

No fix yet
Fix from $2,300 2018-09-03
Debian Linux HIGH 8.8
CVE-2018-15209

ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and …

No fix yet
Fix from $1,950 2018-08-08
Debian Linux HIGH 7.5
CVE-2018-14337

The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory ac…

No fix yet
Fix from $1,950 2018-07-17
Debian Linux HIGH 7.5
CVE-2018-10857

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex reposi…

Mitigation only
Fix from $1,950 2018-07-16
Debian Linux HIGH 7.5
CVE-2018-10859

git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypti…

Mitigation only
Fix from $1,950 2018-07-16
Debian Linux HIGH 8.8
CVE-2018-13139

A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash)…

Mitigation only
Fix from $1,950 2018-07-04
Debian Linux CRITICAL 9.8
CVE-2018-13005

An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.

No fix yet
Fix from $2,300 2018-06-29
Debian Linux MEDIUM 5.5
CVE-2018-12495

The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove…

No fix yet
Fix from $1,600 2018-06-15
Debian Linux HIGH 8.8
CVE-2018-12264

Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.…

No fix yet
Fix from $1,950 2018-06-13
Debian Linux HIGH 8.8
CVE-2018-12265

Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.

No fix yet
Fix from $1,950 2018-06-13
Debian Linux HIGH 7.5
CVE-2018-5184

Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird…

Mitigation only
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 6.5
CVE-2018-11439

The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based bu…

No fix yet
Fix from $1,600 2018-05-30
Debian Linux CRITICAL 9.8
CVE-2018-11531

Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.

No fix yet
Fix from $2,300 2018-05-29
Debian Linux MEDIUM 5.5
CVE-2018-11503

The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove…

Mitigation only
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 5.5
CVE-2018-11504

The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-re…

Mitigation only
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 6.5
CVE-2018-11496

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size vali…

No fix yet
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 5.5
CVE-2018-11468

The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer o…

No fix yet
Fix from $1,600 2018-05-25
Debian Linux MEDIUM 6.5
CVE-2017-18273

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows at…

No fix yet
Fix from $1,600 2018-05-18
Debian Linux MEDIUM 6.5
CVE-2018-11213

An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation f…

No fix yet
Fix from $1,600 2018-05-16