Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2021-25215EPSS 11%

In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, …

Fix: 9.11.31 / 9.16.15+
Fix from $1,950 2021-04-29
Debian Linux MEDIUM 6.5
CVE-2021-25214EPSS 6%

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported…

Fix: 1.0.1.1 / 9.11.31+
Fix from $1,600 2021-04-29
Debian Linux HIGH 7.5
CVE-2021-31863

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine us…

Fix: 4.0.9 / 4.1.3+
Fix from $1,950 2021-04-28
Debian Linux MEDIUM 5.3
CVE-2021-31864

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging …

Fix: 4.0.9 / 4.1.3+
Fix from $1,600 2021-04-28
Debian Linux MEDIUM 5.3
CVE-2021-31865

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

Fix: 4.0.9 / 4.1.3+
Fix from $1,600 2021-04-28
Debian Linux MEDIUM 5.3
CVE-2021-31866

Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in…

Fix: 4.0.9 / 4.1.3+
Fix from $1,600 2021-04-28
Debian Linux HIGH 8.8
CVE-2021-29472

Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitize…

Fix: 1.10.22 / 2.0.13+
Fix from $1,950 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25032

Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability.…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25033

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerabil…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25034

Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25035

Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25038

Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability.…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25039

Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Alt…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25042

Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Altho…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux HIGH 7.5
CVE-2019-25036

Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Althou…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux HIGH 7.5
CVE-2019-25037

Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this i…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux HIGH 7.5
CVE-2019-25040

Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Althoug…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux HIGH 7.5
CVE-2019-25041

Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Alt…

Fix: 1.9.5+
Fix from $1,950 2021-04-27
Debian Linux MEDIUM 5.9
CVE-2019-25031

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT…

Fix: 1.9.5+
Fix from $1,600 2021-04-27
Debian Linux HIGH 7.5
CVE-2021-31598

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files,…

Patch available
Fix from $1,950 2021-04-24
Debian Linux HIGH 7.8
CVE-2021-22204 KEVEPSS 100%

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malici…

Fix: 12.24+
Fix from $1,950 2021-04-23
Debian Linux MEDIUM 5.9
CVE-2021-2161

Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported version…

Fix: after 15.0.2
Fix from $1,600 2021-04-22
Debian Linux MEDIUM 5.3
CVE-2021-2163

Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported version…

Fix: after 15.0.2
Fix from $1,600 2021-04-22
Debian Linux HIGH 7.8
CVE-2021-3497

GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

Fix: 1.18.4+
Fix from $1,950 2021-04-19
Debian Linux HIGH 7.8
CVE-2021-3498

GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.

Fix: 1.18.4+
Fix from $1,950 2021-04-19
Debian Linux MEDIUM 6.5
CVE-2021-31347

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML fil…

Patch available
Fix from $1,600 2021-04-16
Debian Linux MEDIUM 6.5
CVE-2021-31348

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML fil…

Patch available
Fix from $1,600 2021-04-16
Debian Linux MEDIUM 6.5
CVE-2021-31229

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML …

Patch available
Fix from $1,600 2021-04-15
Debian Linux MEDIUM 6.5
CVE-2021-30485

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory …

Patch available
Fix from $1,600 2021-04-11
Debian Linux HIGH 7.5
CVE-2021-1405

A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated…

Fix: after 0.103.1
Fix from $1,950 2021-04-08