Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-9956EPSS 6% In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a d… Debian Linux No fix yet Fix from $1,9502019-03-24 HIGH 8.8 CVE-2019-9656 An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.c… Debian Linux No fix yet Fix from $1,9502019-03-11 HIGH 7.8 CVE-2019-1999 In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privileg… Debian Linux No fix yet Fix from $1,9502019-02-28 HIGH 7.8 CVE-2019-9210 In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted m… Debian Linux No fix yet Fix from $1,9502019-02-27 HIGH 8.8 CVE-2019-9200 A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending… Debian Linux No fix yet Fix from $1,9502019-02-26 HIGH 8.8 CVE-2019-8907 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or… Debian Linux No fix yet Fix from $1,9502019-02-18 MEDIUM 5.0 CVE-2019-8354 An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When t… Debian Linux Mitigation only Fix from $1,6002019-02-15 MEDIUM 5.5 CVE-2019-7665 In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can… Debian Linux No fix yet Fix from $1,6002019-02-09 CRITICAL 9.8 CVE-2019-7653 The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowi… Debian Linux No fix yet Fix from $2,3002019-02-09 CRITICAL 9.8 CVE-2019-3463 Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to … Debian Linux Mitigation only Fix from $2,3002019-02-06 CRITICAL 9.8 CVE-2019-3464 Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restri… Debian Linux Mitigation only Fix from $2,3002019-02-06 HIGH 7.8 CVE-2019-1000018 rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp p… Debian Linux No fix yet Fix from $1,9502019-02-04 HIGH 7.0 CVE-2019-3461 Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mo… Tmpreaper Mitigation only Fix from $1,9502019-02-04 MEDIUM 5.3 CVE-2017-3138EPSS 6% named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel… Debian Linux Mitigation only Fix from $1,6002019-01-16 CRITICAL 9.8 CVE-2019-6256 A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer cr… Debian Linux No fix yet Fix from $2,3002019-01-14 MEDIUM 6.5 CVE-2018-20622 JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. Debian Linux Mitigation only Fix from $1,6002018-12-31 MEDIUM 6.5 CVE-2018-20570 jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read. Debian Linux No fix yet Fix from $1,6002018-12-28 HIGH 7.8 CVE-2018-20196 There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder… Debian Linux No fix yet Fix from $1,9502018-12-18 MEDIUM 5.4 CVE-2018-18245 Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plu… Debian Linux No fix yet Fix from $1,6002018-12-17 HIGH 8.8 CVE-2018-20004 An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a do… Debian Linux No fix yet Fix from $1,9502018-12-10 CRITICAL 9.1 CVE-2018-19857 The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies… Debian Linux No fix yet Fix from $2,3002018-12-05 MEDIUM 5.5 CVE-2018-19777 In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool. Debian Linux No fix yet Fix from $1,6002018-11-30 MEDIUM 6.5 CVE-2018-19758 There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service. Debian Linux No fix yet Fix from $1,6002018-11-30 MEDIUM 6.5 CVE-2018-19661 An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of servic… Debian Linux No fix yet Fix from $1,6002018-11-29 HIGH 8.8 CVE-2018-19540 An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.1… Debian Linux No fix yet Fix from $1,9502018-11-26 MEDIUM 6.5 CVE-2018-19539 An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a… Debian Linux No fix yet Fix from $1,6002018-11-26 MEDIUM 6.5 CVE-2018-19210 In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service a… Debian Linux No fix yet Fix from $1,6002018-11-12 MEDIUM 6.5 CVE-2018-18897 An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo. Debian Linux No fix yet Fix from $1,6002018-11-02 MEDIUM 6.5 CVE-2018-14661 It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vuln… Debian Linux Mitigation only Fix from $1,6002018-10-31 HIGH 7.8 CVE-2018-18654 Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in … Crossroads Mitigation only Fix from $1,9502018-10-26