Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2017-17786

In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-…

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux MEDIUM 5.5
CVE-2017-17788

In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.

Mitigation only
Fix from $1,600 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-17782

In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17784

In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling o…

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17785

In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.5
CVE-2017-17783

In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-17511

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17514

boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote …

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17515

etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might all…

Mitigation only
Fix from $1,950 2017-12-14
Tin HIGH 8.8
CVE-2017-17520

tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might a…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17527

delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the BROWSER environment variable…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux MEDIUM 5.9
CVE-2017-1000385EPSS 22%

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decry…

Mitigation only
Fix from $1,600 2017-12-12
Debian Linux CRITICAL 9.8
CVE-2017-17480EPSS 5%

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou…

Mitigation only
Fix from $2,300 2017-12-08
Debian Linux HIGH 8.1
CVE-2017-8028

In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind…

Mitigation only
Fix from $1,950 2017-11-27
Debian Linux HIGH 7.5
CVE-2017-16944EPSS 63%

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop an…

No fix yet
Fix from $1,950 2017-11-25
Debian Linux HIGH 7.8
CVE-2017-2896

An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a mem…

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 7.8
CVE-2017-2919

An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause …

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 7.1
CVE-2017-16899

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with…

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 7.8
CVE-2017-1000229

Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.

No fix yet
Fix from $1,950 2017-11-17
Debian Linux HIGH 8.8
CVE-2017-16352EPSS 15%

GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Descri…

No fix yet
Fix from $1,950 2017-11-01
Debian Linux MEDIUM 6.5
CVE-2017-16353EPSS 14%

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil…

No fix yet
Fix from $1,600 2017-11-01
Debian Linux HIGH 7.8
CVE-2013-6049

apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors.

Mitigation only
Fix from $1,950 2017-10-20
Debian Linux MEDIUM 5.5
CVE-2017-15642

In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.

Mitigation only
Fix from $1,600 2017-10-19
Debian Linux HIGH 8.8
CVE-2017-15565

In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.

No fix yet
Fix from $1,950 2017-10-17
Debian Linux MEDIUM 5.5
CVE-2017-15370

There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15371

There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15372

There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will le…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux HIGH 8.8
CVE-2017-2887

An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can c…

Mitigation only
Fix from $1,950 2017-10-11
Debian Linux HIGH 7.5
CVE-2017-14975

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is n…

No fix yet
Fix from $1,950 2017-10-02
Debian Linux HIGH 7.5
CVE-2017-14977

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of…

No fix yet
Fix from $1,950 2017-10-02