Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2017-13777

GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the re…

Patch available
Fix from $1,600 2017-08-30
Debian Linux MEDIUM 5.5
CVE-2017-13760

In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.

No fix yet
Fix from $1,600 2017-08-29
Debian Linux HIGH 7.5
CVE-2017-0379

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, rela…

Fix: after 1.8.0
Fix from $1,950 2017-08-29
Debian Linux MEDIUM 5.5
CVE-2017-13755

In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libt…

Patch available
Fix from $1,600 2017-08-29
Debian Linux MEDIUM 5.5
CVE-2017-13756

In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as dem…

Mitigation only
Fix from $1,600 2017-08-29
Debian Linux CRITICAL 9.8
CVE-2017-12865EPSS 6%

Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbit…

Fix: after 1.34
Fix from $2,300 2017-08-29
Debian Linux MEDIUM 6.5
CVE-2017-13737

There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.

Patch available
Fix from $1,600 2017-08-29
Debian Linux MEDIUM 6.5
CVE-2017-12877

Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of servi…

Fix: 6.9.9-6 / 7.0.6-6+
Fix from $1,600 2017-08-28
Xbindkeys Config CRITICAL 9.8
CVE-2014-9513

Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2017-08-28
Debian Linux HIGH 7.5
CVE-2017-11424

In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, t…

Fix: after 1.5.0
Fix from $1,950 2017-08-24
Debian Linux MEDIUM 6.5
CVE-2017-12809

QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of …

Fix: after 2.9.1
Fix from $1,600 2017-08-23
Debian Linux HIGH 8.8
CVE-2017-12904EPSS 6%

Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attack…

Patch available
Fix from $1,950 2017-08-23
Debian Linux CRITICAL 9.8
CVE-2017-13139

In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.

Fix: after 6.9.9-0
Fix from $2,300 2017-08-23
Debian Linux MEDIUM 6.5
CVE-2017-13145

In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, lead…

Fix: after 6.9.8-7
Fix from $1,600 2017-08-23
Debian Linux HIGH 8.8
CVE-2017-5208

Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a cra…

Fix: 0.31.1+
Fix from $1,950 2017-08-22
Debian Linux MEDIUM 6.5
CVE-2017-13063

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux MEDIUM 6.5
CVE-2017-13064

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux MEDIUM 6.5
CVE-2017-13065

GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux HIGH 8.8
CVE-2017-12935

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColo…

Patch available
Fix from $1,950 2017-08-18
Debian Linux HIGH 8.8
CVE-2017-12936EPSS 25%

The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.

Patch available
Fix from $1,950 2017-08-18
Debian Linux HIGH 8.8
CVE-2017-12937

The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.

Patch available
Fix from $1,950 2017-08-18
Debian Linux HIGH 8.8
CVE-2017-12862

In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If …

Fix: after 3.3.0
Fix from $1,950 2017-08-15
Debian Linux HIGH 8.8
CVE-2017-12863

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_pitch. If the image is from r…

Fix: after 3.3.0
Fix from $1,950 2017-08-15
Debian Linux HIGH 8.8
CVE-2017-12864

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is…

Fix: after 3.3.0
Fix from $1,950 2017-08-15
Debian Linux HIGH 7.5
CVE-2015-3405EPSS 5%

ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when t…

Patch available
Fix from $1,950 2017-08-09
Debian Linux MEDIUM 6.5
CVE-2017-10243

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are …

Patch available
Fix from $1,600 2017-08-08
Debian Linux HIGH 7.5
CVE-2017-10176EPSS 5%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected ar…

Fix: after 11.70.1
Fix from $1,950 2017-08-08
Debian Linux MEDIUM 6.8
CVE-2017-10198

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected ar…

Patch available
Fix from $1,600 2017-08-08
Debian Linux MEDIUM 5.9
CVE-2017-10135

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Jav…

Patch available
Fix from $1,600 2017-08-08
Debian Linux CRITICAL 9.6
CVE-2017-10096

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u…

Patch available
Fix from $2,300 2017-08-08