Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2020-20453

FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service

Patch available
Fix from $1,600 2021-05-25
Debian Linux HIGH 7.5
CVE-2020-20450

FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.

Mitigation only
Fix from $1,950 2021-05-25
Debian Linux HIGH 7.5
CVE-2020-20451

Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.

Patch available
Fix from $1,950 2021-05-25
Debian Linux MEDIUM 6.5
CVE-2020-20445

FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious user to cause a Denial of Service.

Patch available
Fix from $1,600 2021-05-25
Debian Linux MEDIUM 6.5
CVE-2020-20446

FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service.

No fix yet
Fix from $1,600 2021-05-25
Debian Linux HIGH 7.5
CVE-2020-21041

Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a …

Patch available
Fix from $1,950 2021-05-24
Debian Linux CRITICAL 9.1
CVE-2020-36330

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this …

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Debian Linux HIGH 8.8
CVE-2021-31439

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authenticat…

Fix: 3.1.13 / 6.2.3-25426-3+
Fix from $1,950 2021-05-21
Debian Linux HIGH 8.8
CVE-2021-3518

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with l…

Fix: 2.9.11+
Fix from $1,950 2021-05-18
Debian Linux HIGH 7.5
CVE-2020-25709

A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an …

Fix: 2.4.56 / 10.14.6+
Fix from $1,950 2021-05-18
Debian Linux HIGH 7.5
CVE-2021-32918

An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memo…

Fix: 0.11.9+
Fix from $1,950 2021-05-13
Debian Linux HIGH 7.5
CVE-2021-32919

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature f…

Fix: 0.11.9+
Fix from $1,950 2021-05-13
Debian Linux HIGH 7.5
CVE-2021-32920

Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.

Fix: 0.11.9+
Fix from $1,950 2021-05-13
Debian Linux MEDIUM 5.3
CVE-2021-32917

An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP accou…

Fix: 0.11.9+
Fix from $1,600 2021-05-13
Debian Linux HIGH 7.5
CVE-2021-20181

A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause …

Fix: after 5.2.0
Fix from $1,950 2021-05-13
Debian Linux HIGH 7.5
CVE-2020-27840

A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces …

Fix: 4.12.13 / 4.13.6+
Fix from $1,950 2021-05-12
Debian Linux HIGH 7.5
CVE-2021-20277

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a…

Fix: 4.12.13 / 4.13.6+
Fix from $1,950 2021-05-12
Debian Linux HIGH 7.5
CVE-2021-20309

A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c m…

Fix: 6.9.12 / 7.0.11-0+
Fix from $1,950 2021-05-11
Debian Linux HIGH 7.5
CVE-2021-20312

A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined beha…

Fix: 7.0.11-0+
Fix from $1,950 2021-05-11
Debian Linux HIGH 7.5
CVE-2021-20313

A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. T…

Fix: 7.0.11-0+
Fix from $1,950 2021-05-11
Debian Linux MEDIUM 5.3
CVE-2020-26139EPSS 6%

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet s…

Patch available
Fix from $1,600 2021-05-11
Debian Linux MEDIUM 6.1
CVE-2021-3507

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block…

Fix: after 6.0.0
Fix from $1,600 2021-05-06
Debian Linux CRITICAL 9.8
CVE-2021-20204

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This …

Mitigation only
Fix from $2,300 2021-05-06
Debian Linux CRITICAL 9.8
CVE-2021-31870

An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-31872

An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overf…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-31873

An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer over…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux HIGH 7.5
CVE-2021-31871

An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems.

Fix: 2.0.9+
Fix from $1,950 2021-04-30
Debian Linux HIGH 7.8
CVE-2020-18032

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause …

Fix: 2.46.0+
Fix from $1,950 2021-04-29
Debian Linux MEDIUM 5.5
CVE-2021-21417

fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be tr…

Fix: 2.1.8+
Fix from $1,600 2021-04-29
Debian Linux CRITICAL 9.8
CVE-2021-25216EPSS 82%

In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition,…

Fix: 1.0.1.1 / 9.11.31+
Fix from $2,300 2021-04-29