Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2020-36281

Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.

Fix: 1.80.0+
Fix from $1,950 2021-03-12
Debian Linux MEDIUM 5.3
CVE-2021-28153

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a…

Fix: 2.66.8+
Fix from $1,600 2021-03-11
Debian Linux HIGH 8.2
CVE-2021-21381

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before versi…

Fix: 1.10.2+
Fix from $1,950 2021-03-11
Debian Linux MEDIUM 6.5
CVE-2021-21375

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.10
Fix from $1,600 2021-03-10
Debian Linux HIGH 7.8
CVE-2020-35524

A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can l…

Fix: 4.2.0+
Fix from $1,950 2021-03-09
Debian Linux MEDIUM 5.5
CVE-2021-20255

A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing…

Patch available
Fix from $1,600 2021-03-09
Debian Linux HIGH 7.8
CVE-2020-35523

An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary co…

Fix: 4.2.0+
Fix from $1,950 2021-03-09
Debian Linux MEDIUM 5.9
CVE-2021-21295EPSS 19%

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol serv…

Fix: 1.16.0 / 4.1.60+
Fix from $1,600 2021-03-09
Debian Linux MEDIUM 5.5
CVE-2021-20243

A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefin…

Fix: 7.0.10-62+
Fix from $1,600 2021-03-09
Debian Linux MEDIUM 5.5
CVE-2021-20241

A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined beha…

Fix: 6.9.11-62 / 7.0.10-62+
Fix from $1,600 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-20276

A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-20272

A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-20273

A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-20275

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Debian Linux CRITICAL 9.8
CVE-2020-35636

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::re…

No fix yet
Fix from $2,300 2021-03-04
Debian Linux MEDIUM 5.5
CVE-2020-27618

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371…

Fix: after 2.32
Fix from $1,600 2021-02-26
Debian Linux MEDIUM 6.1
CVE-2021-21330

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerabili…

Fix: 3.7.4+
Fix from $1,600 2021-02-26
Debian Linux HIGH 7.8
CVE-2021-3410

A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arb…

No fix yet
Fix from $1,950 2021-02-23
Debian Linux HIGH 7.4
CVE-2021-20247

A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or…

Fix: 1.3.5 / 1.4.1+
Fix from $1,950 2021-02-23
Debian Linux CRITICAL 9.8
CVE-2021-26120EPSS 82%

Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

Fix: 3.1.39+
Fix from $2,300 2021-02-22
Debian Linux HIGH 7.5
CVE-2021-26119EPSS 9%

Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.

Fix: 3.1.39+
Fix from $1,950 2021-02-22
Debian Linux HIGH 7.8
CVE-2021-27379

An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause …

Fix: 4.12.0+
Fix from $1,950 2021-02-18
Debian Linux HIGH 8.1
CVE-2020-8625EPSS 64%

BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's…

Fix: 1.0.1.1+
Fix from $1,950 2021-02-17
Debian Linux HIGH 7.8
CVE-2021-26720

avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local att…

Fix: after 0.8-4
Fix from $1,950 2021-02-17
Debian Linux HIGH 8.8
CVE-2021-27229

Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.

Fix: 1.3.4+
Fix from $1,950 2021-02-16
Debian Linux MEDIUM 6.1
CVE-2021-26929

An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacke…

Fix: after 5.2.22
Fix from $1,600 2021-02-14
Debian Linux HIGH 7.5
CVE-2021-27212EPSS 64%

In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a craft…

Fix: after 2.4.57
Fix from $1,950 2021-02-14
Debian Linux HIGH 7.2
CVE-2021-21311 KEVEPSS 90%

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for…

Fix: 4.7.9+
Fix from $1,950 2021-02-11
Debian Linux HIGH 7.5
CVE-2020-35498EPSS 8%

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a special…

Fix: 2.5.12 / 2.6.10+
Fix from $1,950 2021-02-11
Debian Linux CRITICAL 9.8
CVE-2021-27135EPSS 8%

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combi…

Fix: 366+
Fix from $2,300 2021-02-10