Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2020-35533

In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading dat…

Patch available
Fix from $1,600 2022-09-01
Debian Linux MEDIUM 6.5
CVE-2022-2519

There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1

Patch available
Fix from $1,600 2022-08-31
Debian Linux MEDIUM 6.5
CVE-2022-2520

A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when readi…

Patch available
Fix from $1,600 2022-08-31
Debian Linux MEDIUM 6.5
CVE-2022-2521

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can…

Patch available
Fix from $1,600 2022-08-31
Debian Linux MEDIUM 6.5
CVE-2021-46837

res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows a…

Fix: 16.16.2 / 17.9.3+
Fix from $1,600 2022-08-30
Debian Linux HIGH 7.5
CVE-2022-39028

telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In…

Fix: after 2.3
Fix from $1,950 2022-08-30
Debian Linux HIGH 7.5
CVE-2022-25857

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collection…

Fix: 1.31+
Fix from $1,950 2022-08-30
Debian Linux HIGH 7.8
CVE-2022-38784

Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Process…

Fix: after 22.08.0
Fix from $1,950 2022-08-30
Debian Linux MEDIUM 5.5
CVE-2022-2953

LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafte…

Fix: after 4.4.0
Fix from $1,600 2022-08-29
Debian Linux HIGH 7.4
CVE-2021-3563

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password co…

No fix yet
Fix from $1,950 2022-08-26
Debian Linux HIGH 7.5
CVE-2022-2255

A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the…

Fix: 4.9.3+
Fix from $1,950 2022-08-25
Debian Linux MEDIUM 5.5
CVE-2021-4214

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG…

No fix yet
Fix from $1,600 2022-08-24
Debian Linux HIGH 7.8
CVE-2021-3999

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exact…

Fix: 2.31+
Fix from $1,950 2022-08-24
Debian Linux HIGH 7.8
CVE-2020-35511

A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.

Mitigation only
Fix from $1,950 2022-08-23
Debian Linux HIGH 7.5
CVE-2021-20298

A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all me…

Fix: after 2.5.7
Fix from $1,950 2022-08-23
Debian Linux MEDIUM 6.8
CVE-2021-20316

A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify shar…

Fix: 4.15.0+
Fix from $1,600 2022-08-23
Debian Linux MEDIUM 5.5
CVE-2021-3800

A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivil…

Fix: 2.62.5 / 2.63.6+
Fix from $1,600 2022-08-23
Debian Linux HIGH 7.1
CVE-2020-27792

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attac…

Fix: after 9.50
Fix from $1,950 2022-08-19
Debian Linux MEDIUM 5.5
CVE-2022-26373

Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable i…

Mitigation only
Fix from $1,600 2022-08-18
Debian Linux HIGH 7.5
CVE-2020-21365

Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a …

Fix: after 0.12.5
Fix from $1,950 2022-08-15
Debian Linux MEDIUM 6.7
CVE-2022-20369

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation…

Patch available
Fix from $1,600 2022-08-11
Debian Linux CRITICAL 9.8
CVE-2022-37452

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

Fix: 4.95+
Fix from $2,300 2022-08-07
Debian Linux CRITICAL 9.8
CVE-2022-32292

In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in receiv…

Fix: after 1.41
Fix from $2,300 2022-08-03
Debian Linux HIGH 8.1
CVE-2022-32293

In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading t…

Fix: after 1.41
Fix from $1,950 2022-08-03
Debian Linux MEDIUM 5.5
CVE-2022-2598

Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.

Fix: 9.0.0100+
Fix from $1,600 2022-08-01
Debian Linux HIGH 8.0
CVE-2022-30287EPSS 71%

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This th…

Fix: after 5.2.22
Fix from $1,950 2022-07-28
Debian Linux MEDIUM 6.5
CVE-2022-2553

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes …

Fix: after 1.0
Fix from $1,600 2022-07-28
Debian Linux HIGH 8.8
CVE-2022-33745

insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may …

Patch available
Fix from $1,950 2022-07-26
Debian Linux HIGH 8.8
CVE-2022-26307

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a sin…

Fix: 7.2.7 / 7.3.3+
Fix from $1,950 2022-07-25
Debian Linux HIGH 7.5
CVE-2022-26306

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a sin…

Fix: 7.2.7 / 7.3.3+
Fix from $1,950 2022-07-25