Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2020-21675

A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via conv…

Patch available
Fix from $1,600 2021-08-10
Debian Linux MEDIUM 5.5
CVE-2020-21676

A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS)…

Patch available
Fix from $1,600 2021-08-10
Debian Linux CRITICAL 9.8
CVE-2021-38173

Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize…

Fix: 0.31.2+
Fix from $2,300 2021-08-07
Debian Linux MEDIUM 5.3
CVE-2021-38165

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may ap…

Fix: after 2.8.9
Fix from $1,600 2021-08-07
Debian Linux MEDIUM 5.5
CVE-2021-3566

Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that refer…

Fix: 4.3+
Fix from $1,600 2021-08-05
Debian Linux MEDIUM 5.5
CVE-2021-38114

libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-2013-0868.

Patch available
Fix from $1,600 2021-08-04
Debian Linux HIGH 8.8
CVE-2021-35472

An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that…

Fix: after 2.0.11
Fix from $1,950 2021-07-30
Debian Linux HIGH 7.5
CVE-2021-32558EPSS 9%

An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Aster…

Fix: 13.38.3 / 16.19.1+
Fix from $1,950 2021-07-30
Debian Linux HIGH 7.0
CVE-2021-31799

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

Fix: 6.3.1 / 9.2.6.1+
Fix from $1,950 2021-07-30
Debian Linux HIGH 7.5
CVE-2021-31292

An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (D…

Patch available
Fix from $1,950 2021-07-26
Debian Linux MEDIUM 5.9
CVE-2021-32686

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 2.11.1+
Fix from $1,600 2021-07-23
Debian Linux HIGH 7.5
CVE-2021-32785

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenti…

Fix: 2.4.9+
Fix from $1,950 2021-07-22
Debian Linux CRITICAL 9.1
CVE-2021-35942

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called…

Fix: 2.31+
Fix from $2,300 2021-07-22
Debian Linux HIGH 7.5
CVE-2021-35063

Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."

Fix: 5.0.7 / 6.0.3+
Fix from $1,950 2021-07-22
Debian Linux HIGH 7.5
CVE-2021-36222EPSS 10%

ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows rem…

Fix: 1.18.4 / 1.19.2+
Fix from $1,950 2021-07-22
Debian Linux MEDIUM 5.5
CVE-2020-19609

Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause…

Fix: 1.18.0+
Fix from $1,600 2021-07-21
Debian Linux HIGH 7.8
CVE-2019-25051

objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config…

Patch available
Fix from $1,950 2021-07-20
Debian Linux HIGH 7.5
CVE-2020-36423

An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't prop…

Fix: 2.16.7 / 2.23.0+
Fix from $1,950 2021-07-19
Debian Linux HIGH 7.5
CVE-2020-36426

An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).

Fix: 2.7.17 / 2.16.8+
Fix from $1,950 2021-07-19
Debian Linux MEDIUM 5.3
CVE-2020-36421

An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure encla…

Fix: 2.16.7 / 2.23.0+
Fix from $1,600 2021-07-19
Debian Linux MEDIUM 5.3
CVE-2020-36422

An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, m…

Fix: 2.16.7 / 2.23.0+
Fix from $1,600 2021-07-19
Debian Linux MEDIUM 5.3
CVE-2020-36425

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocati…

Fix: 2.7.17 / 2.16.8+
Fix from $1,600 2021-07-19
Debian Linux HIGH 7.5
CVE-2021-36773

uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web si…

Fix: 1.4.2 / 1.36.2+
Fix from $1,950 2021-07-18
Debian Linux HIGH 8.8
CVE-2021-32743

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.10 / 2.12.5+
Fix from $1,950 2021-07-15
Debian Linux HIGH 8.8
CVE-2021-32739

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.10 / 2.12.5+
Fix from $1,950 2021-07-15
Debian Linux MEDIUM 6.5
CVE-2020-19716

A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).

Mitigation only
Fix from $1,600 2021-07-13
Debian Linux HIGH 7.5
CVE-2021-35197

In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot accou…

Fix: 1.31.15 / 1.35.3+
Fix from $1,950 2021-07-02
Debian Linux MEDIUM 5.5
CVE-2021-3630

An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to cras…

Fix: 3.5.28+
Fix from $1,600 2021-06-30
Debian Linux HIGH 7.8
CVE-2021-3500

A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to …

Fix: after 3.5.28
Fix from $1,950 2021-06-24
Debian Linux HIGH 7.8
CVE-2021-32490

A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application …

Fix: after 3.5.28
Fix from $1,950 2021-06-24