Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2021-32491

A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to applicati…

Fix: after 3.5.28
Fix from $1,950 2021-06-24
Debian Linux HIGH 7.8
CVE-2021-32492

A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to appl…

Fix: after 3.5.28
Fix from $1,950 2021-06-24
Debian Linux HIGH 7.8
CVE-2021-32493

A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to applic…

Fix: after 3.5.28
Fix from $1,950 2021-06-24
Debian Linux MEDIUM 5.5
CVE-2021-27345

A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a c…

Patch available
Fix from $1,600 2021-06-10
Debian Linux MEDIUM 5.5
CVE-2021-27347

Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed …

Patch available
Fix from $1,600 2021-06-10
Debian Linux MEDIUM 5.5
CVE-2020-25467

A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) v…

Patch available
Fix from $1,600 2021-06-10
Debian Linux HIGH 8.8
CVE-2020-24489

Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.

Mitigation only
Fix from $1,950 2021-06-09
Debian Linux MEDIUM 6.5
CVE-2021-0089

Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local acces…

Mitigation only
Fix from $1,600 2021-06-09
Debian Linux MEDIUM 6.5
CVE-2020-24511

Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via l…

Fix: 20210608+
Fix from $1,600 2021-06-09
Debian Linux MEDIUM 6.5
CVE-2020-24513

Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information di…

Mitigation only
Fix from $1,600 2021-06-09
Debian Linux CRITICAL 9.8
CVE-2021-33833

ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A …

Fix: after 1.39
Fix from $2,300 2021-06-09
Debian Linux MEDIUM 5.5
CVE-2021-26313

Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution…

Mitigation only
Fix from $1,600 2021-06-09
Debian Linux MEDIUM 5.3
CVE-2021-28169EPSS 78%

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access pro…

Fix: 9.4.41 / 10.0.3+
Fix from $1,600 2021-06-09
Debian Linux HIGH 7.5
CVE-2021-33560

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack again…

Fix: 1.8.8 / 1.9.3+
Fix from $1,950 2021-06-08
Debian Linux HIGH 7.5
CVE-2021-28091

Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

Fix: 2.7.0+
Fix from $1,950 2021-06-04
Debian Linux HIGH 7.5
CVE-2021-33054

SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network ac…

Fix: 2.4.1 / 5.1.1+
Fix from $1,950 2021-06-04
Debian Linux MEDIUM 6.5
CVE-2020-22054

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.

No fix yet
Fix from $1,600 2021-06-02
Debian Linux HIGH 8.8
CVE-2015-1877

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which all…

Patch available
Fix from $1,950 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2020-22046

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.

No fix yet
Fix from $1,600 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2020-22048

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.

No fix yet
Fix from $1,600 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2020-22049

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.

No fix yet
Fix from $1,600 2021-06-02
Debian Linux MEDIUM 5.5
CVE-2021-3468

A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is no…

Fix: after 0.8
Fix from $1,600 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2019-12067

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_…

Patch available
Fix from $1,600 2021-06-02
Debian Linux HIGH 8.2
CVE-2021-3546

An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The …

Fix: after 6.0.0
Fix from $1,950 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2021-3544

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contr…

Fix: after 6.0.0
Fix from $1,600 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2021-3545

An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. T…

Fix: after 6.0.0
Fix from $1,600 2021-06-02
Debian Linux HIGH 7.1
CVE-2018-10195

lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size…

Fix: after 0.12.20
Fix from $1,950 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2020-22044

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.

Patch available
Fix from $1,600 2021-06-01
Debian Linux MEDIUM 6.5
CVE-2020-22037

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

Patch available
Fix from $1,600 2021-06-01
Debian Linux MEDIUM 6.5
CVE-2020-22041

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.

No fix yet
Fix from $1,600 2021-06-01