Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.9
CVE-2017-11104

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key na…

Fix: after 2.4.4
Fix from $1,600 2017-07-08
Debian Linux CRITICAL 9.8
CVE-2016-4000EPSS 6%

Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

Patch available
Fix from $2,300 2017-07-06
Debian Linux HIGH 7.5
CVE-2017-9524

The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a d…

Fix: after 2.9.1
Fix from $1,950 2017-07-06
Debian Linux HIGH 8.2
CVE-2017-2295

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. …

Fix: after 4.10.0
Fix from $1,950 2017-07-05
Debian Linux HIGH 8.8
CVE-2017-9992

Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x bef…

Fix: 2.8.12 / 3.0.8+
Fix from $1,950 2017-06-28
Debian Linux HIGH 7.8
CVE-2017-9994

libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pi…

Fix: 2.8.12 / 3.0.8+
Fix from $1,950 2017-06-28
Debian Linux HIGH 7.5
CVE-2017-9993EPSS 16%

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filenam…

Fix: 2.8.12 / 3.1.9+
Fix from $1,950 2017-06-28
Debian Linux MEDIUM 6.5
CVE-2017-9988

The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NUL…

No fix yet
Fix from $1,600 2017-06-28
Debian Linux MEDIUM 6.5
CVE-2017-9989

util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) at…

No fix yet
Fix from $1,600 2017-06-28
Debian Linux MEDIUM 6.5
CVE-2017-9936EPSS 7%

In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service att…

No fix yet
Fix from $1,600 2017-06-26
Debian Linux MEDIUM 5.5
CVE-2017-9928

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service vi…

Patch available
Fix from $1,600 2017-06-26
Debian Linux MEDIUM 5.5
CVE-2017-9929

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service v…

Patch available
Fix from $1,600 2017-06-26
Debian Linux MEDIUM 5.5
CVE-2017-9868

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic infor…

Fix: after 1.4.12
Fix from $1,600 2017-06-25
Debian Linux MEDIUM 5.5
CVE-2017-9865

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over…

Mitigation only
Fix from $1,600 2017-06-25
Debian Linux HIGH 7.8
CVE-2017-9776

Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of …

Fix: after 0.55.0
Fix from $1,950 2017-06-22
Debian Linux MEDIUM 6.5
CVE-2017-9775

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) vi…

Fix: after 0.55.0
Fix from $1,600 2017-06-22
Debian Linux HIGH 7.8
CVE-2017-9780

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example set…

Fix: after 0.8.6
Fix from $1,950 2017-06-21
Debian Linux MEDIUM 5.5
CVE-2017-9373

Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of ser…

Fix: after 2.8.1.1
Fix from $1,600 2017-06-16
Debian Linux MEDIUM 5.5
CVE-2017-9375

QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service …

Fix: after 2.8.1.1
Fix from $1,600 2017-06-16
Debian Linux MEDIUM 5.5
CVE-2017-9503

QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a…

Fix: after 2.9.1
Fix from $1,600 2017-06-16
Debian Linux HIGH 7.5
CVE-2017-9735EPSS 6%

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by obser…

Fix: 9.2.22 / 9.3.20+
Fix from $1,950 2017-06-16
Debian Linux HIGH 7.8
CVE-2017-4966

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb…

Mitigation only
Fix from $1,950 2017-06-13
Debian Linux MEDIUM 6.1
CVE-2017-4965

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb…

Mitigation only
Fix from $1,600 2017-06-13
Debian Linux MEDIUM 6.1
CVE-2017-4967

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb…

Mitigation only
Fix from $1,600 2017-06-13
Debian Linux HIGH 8.8
CVE-2017-9324

In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable o…

Fix: after 5.0.19
Fix from $1,950 2017-06-12
Debian Linux HIGH 7.8
CVE-2017-9527

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and applicati…

Fix: after 1.2.0
Fix from $1,950 2017-06-11
Debian Linux HIGH 7.5
CVE-2017-0376

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_…

Fix: 0.3.0.8+
Fix from $1,950 2017-06-09
Debian Linux MEDIUM 6.7
CVE-2017-9525

In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to…

Fix: after 3.0pl1-128.
Fix from $1,600 2017-06-09
Debian Linux HIGH 7.5
CVE-2017-9022

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause …

Fix: after 5.5.2
Fix from $1,950 2017-06-08
Debian Linux MEDIUM 5.6
CVE-2017-9310

QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (inf…

Fix: after 2.8.1.1
Fix from $1,600 2017-06-08