Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2021-30130

phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.

Fix: 2.0.31 / 3.0.7+
Fix from $1,950 2021-04-06
Debian Linux CRITICAL 9.8
CVE-2021-30164

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.

Fix: 4.0.8 / 4.1.2+
Fix from $2,300 2021-04-06
Debian Linux HIGH 7.5
CVE-2021-30163

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have chang…

Fix: 4.0.8 / 4.1.2+
Fix from $1,950 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2020-36306

Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

Fix: 4.0.7 / 4.1.1+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2020-36307

Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

Fix: 4.0.7 / 4.1.1+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 5.3
CVE-2019-25026

Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.

Fix: 3.4.13 / 4.0.6+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 5.3
CVE-2020-36308

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti…

Fix: 4.0.7 / 4.1.1+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2021-30154

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* me…

Fix: 1.31.12 / 1.35.2+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2021-30157

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChang…

Fix: 1.31.12 / 1.35.2+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 5.3
CVE-2021-30158

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. Thi…

Fix: 1.31.12 / 1.35.2+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2021-30151

Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

Fix: after 6.2.0
Fix from $1,600 2021-04-06
Debian Linux CRITICAL 9.8
CVE-2021-20308

Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-…

Fix: after 1.9.11
Fix from $2,300 2021-04-05
Debian Linux CRITICAL 9.8
CVE-2021-1871 KEVEPSS 7%

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update…

Fix: 10.15.7 / 11.2+
Fix from $2,300 2021-04-02
Debian Linux MEDIUM 5.5
CVE-2020-10001

An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, …

Fix: 11.1.0+
Fix from $1,600 2021-04-02
Debian Linux MEDIUM 5.3
CVE-2021-20296

A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression f…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-04-01
Debian Linux MEDIUM 5.5
CVE-2021-3477

There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be …

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.5
CVE-2021-3478

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.5
CVE-2021-3479

There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.3
CVE-2021-3475

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-30
Debian Linux MEDIUM 5.3
CVE-2021-3476

A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to Open…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-30
Debian Linux MEDIUM 5.3
CVE-2021-3474

There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHu…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-30
Debian Linux MEDIUM 5.9
CVE-2021-21409

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol serv…

Fix: 4.1.61+
Fix from $1,600 2021-03-30
Debian Linux HIGH 7.5
CVE-2021-29376

ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC…

Fix: 20210314+
Fix from $1,950 2021-03-30
Debian Linux HIGH 7.2
CVE-2021-23358

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template fu…

Fix: 1.12.1 / 1.13.0-2+
Fix from $1,950 2021-03-29
Debian Linux MEDIUM 5.3
CVE-2021-28963

Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

Fix: 3.2.1+
Fix from $1,600 2021-03-22
Debian Linux MEDIUM 6.1
CVE-2021-28957

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the …

Fix: 4.6.3+
Fix from $1,600 2021-03-21
Debian Linux HIGH 8.6
CVE-2020-25097EPSS 8%

An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Req…

Fix: 4.14 / 5.0.5+
Fix from $1,950 2021-03-19
Debian Linux HIGH 7.5
CVE-2021-27291

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions…

Fix: 2.7.4+
Fix from $1,950 2021-03-17
Shadow HIGH 7.8
CVE-2017-20002

The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local user…

No fix yet
Fix from $1,950 2021-03-17
Courier Authlib HIGH 7.5
CVE-2021-28374

The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissio…

Fix: 0.71.1-2+
Fix from $1,950 2021-03-15