Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2020-36244

The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute a…

Fix: 2.18.6+
Fix from $2,300 2021-02-10
Debian Linux CRITICAL 9.8
CVE-2021-26937EPSS 9%

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly …

Fix: after 4.8.0
Fix from $2,300 2021-02-09
Debian Linux HIGH 8.8
CVE-2021-26675

A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.

Fix: 1.39+
Fix from $1,950 2021-02-09
Debian Linux MEDIUM 6.5
CVE-2021-26676

gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs i…

Fix: 1.39+
Fix from $1,600 2021-02-09
Debian Linux HIGH 7.0
CVE-2021-26910

Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation an…

Fix: 0.9.64.4+
Fix from $1,950 2021-02-08
Debian Linux MEDIUM 5.5
CVE-2021-21290

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol serv…

Fix: 4.1.59+
Fix from $1,600 2021-02-08
Debian Linux MEDIUM 5.5
CVE-2021-20176

A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submits a crafted file that is proc…

Fix: 6.9.11-57 / 7.0.10-56+
Fix from $1,600 2021-02-06
Debian Linux MEDIUM 6.3
CVE-2020-17380

A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA tra…

Fix: after 5.0.0
Fix from $1,600 2021-01-30
Debian Linux HIGH 7.5
CVE-2021-3326

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding,…

Fix: after 11.60.3
Fix from $1,950 2021-01-27
Debian Linux HIGH 7.5
CVE-2020-36225

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of servic…

Fix: 2.4.57 / 11.4+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36226

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36227EPSS 78%

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of s…

Fix: 2.4.57 / 11.4+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36228EPSS 83%

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting …

Fix: 2.4.57 / 11.4+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36229

A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in deni…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36230EPSS 12%

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, result…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36221EPSS 84%

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in de…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36222EPSS 78%

A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of servic…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36223

A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36224

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.8
CVE-2020-27814

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash…

Fix: 2.4.0+
Fix from $1,950 2021-01-26
Debian Linux MEDIUM 6.5
CVE-2021-21239

PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vuln…

Fix: 6.5.0+
Fix from $1,600 2021-01-21
Debian Linux MEDIUM 5.4
CVE-2020-14410

SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafte…

Fix: after 2.0.20
Fix from $1,600 2021-01-19
Debian Linux MEDIUM 6.5
CVE-2021-3181

rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences…

Fix: after 2.0.4
Fix from $1,600 2021-01-19
Debian Linux MEDIUM 6.8
CVE-2020-28473

The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can…

Fix: 0.12.19+
Fix from $1,600 2021-01-18
Debian Linux HIGH 8.8
CVE-2021-21261

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` ser…

Fix: 1.8.5 / 1.10.0+
Fix from $1,950 2021-01-14
Debian Linux HIGH 7.8
CVE-2020-35459

An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute comma…

Fix: after 4.2.1
Fix from $1,950 2021-01-12
Debian Linux MEDIUM 6.8
CVE-2021-0308

In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri…

Mitigation only
Fix from $1,600 2021-01-11
Debian Linux HIGH 7.8
CVE-2020-26664

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafte…

Fix: 3.0.12+
Fix from $1,950 2021-01-08
Debian Linux HIGH 7.1
CVE-2021-1056

NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely hono…

Fix: 390.141 / 450.102.04+
Fix from $1,950 2021-01-08
Debian Linux HIGH 8.1
CVE-2020-36183

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-07