Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.6
CVE-2017-9330

QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (inf…

Fix: after 2.8.1.1
Fix from $1,600 2017-06-08
Debian Linux HIGH 7.5
CVE-2017-9468

In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can…

Fix: after 1.0.2
Fix from $1,950 2017-06-07
Debian Linux HIGH 7.5
CVE-2017-9469EPSS 6%

In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memo…

Fix: after 1.0.2
Fix from $1,950 2017-06-07
Debian Linux HIGH 8.8
CVE-2017-9462EPSS 22%

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary cod…

Fix: 4.1.3+
Fix from $1,950 2017-06-06
Debian Linux MEDIUM 6.5
CVE-2017-9403

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause …

Mitigation only
Fix from $1,600 2017-06-02
Debian Linux MEDIUM 6.5
CVE-2017-9404

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to …

Mitigation only
Fix from $1,600 2017-06-02
Debian Linux MEDIUM 6.5
CVE-2017-9406

In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via …

Mitigation only
Fix from $1,600 2017-06-02
Debian Linux MEDIUM 6.5
CVE-2017-9408

In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of …

Mitigation only
Fix from $1,600 2017-06-02
Debian Linux CRITICAL 9.8
CVE-2017-7494 KEVEPSS 99%

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to up…

Fix: 4.4.0 / 4.4.14+
Fix from $2,300 2017-05-30
Debian Linux MEDIUM 6.5
CVE-2017-9287EPSS 7%

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can cr…

Fix: after 2.4.44
Fix from $1,600 2017-05-29
Debian Linux MEDIUM 6.5
CVE-2017-9216

libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_h…

Patch available
Fix from $1,600 2017-05-24
Debian Linux MEDIUM 5.5
CVE-2017-8312

Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a craft…

Fix: 2.2.6+
Fix from $1,600 2017-05-23
Debian Linux MEDIUM 5.5
CVE-2017-8314

Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.

Fix: after 17.1
Fix from $1,600 2017-05-23
Debian Linux CRITICAL 9.8
CVE-2017-9214

In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsi…

Patch available
Fix from $2,300 2017-05-23
Debian Linux HIGH 7.5
CVE-2017-8309

Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly…

Fix: after 2.9.1
Fix from $1,950 2017-05-23
Debian Linux MEDIUM 6.5
CVE-2017-8379

Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of ser…

Fix: after 2.9.1
Fix from $1,600 2017-05-23
Debian Linux CRITICAL 9.8
CVE-2016-9841EPSS 8%

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Fix: after 8.0.12
Fix from $2,300 2017-05-23
Debian Linux CRITICAL 9.8
CVE-2016-9843EPSS 6%

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian C…

Fix: after 8.0.12
Fix from $2,300 2017-05-23
Debian Linux HIGH 8.8
CVE-2016-9840

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Fix: after 8.0.12
Fix from $1,950 2017-05-23
Debian Linux HIGH 8.8
CVE-2016-9842EPSS 5%

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shi…

Fix: after 8.0.12
Fix from $1,950 2017-05-23
Debian Linux HIGH 8.8
CVE-2017-6891EPSS 6%

Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer…

Patch available
Fix from $1,950 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9141

In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c becau…

Patch available
Fix from $1,600 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9142

In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing check…

Patch available
Fix from $1,600 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9143

In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial of service (memory leak) via a crafted .art file.

Patch available
Fix from $1,600 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9144

In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.

Patch available
Fix from $1,600 2017-05-22
Debian Linux CRITICAL 9.8
CVE-2017-2518EPSS 5%

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Debian Linux CRITICAL 9.8
CVE-2017-2519

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Debian Linux CRITICAL 9.8
CVE-2017-2520

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Debian Linux HIGH 7.5
CVE-2017-9098

ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive infor…

Fix: 1.3.24 / 6.9.8-1+
Fix from $1,950 2017-05-19
Debian Linux HIGH 8.8
CVE-2017-9078EPSS 5%

The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners…

Fix: 2017.75+
Fix from $1,950 2017-05-19