Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.1
CVE-2020-36179EPSS 21%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common…

Patch available
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36180EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Patch available
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36182EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36184EPSS 10%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Patch available
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36185EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36186EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36187EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36188EPSS 11%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36189

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36181EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Patch available
Fix from $1,950 2021-01-06
Debian Linux HIGH 7.8
CVE-2020-27844

A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg dur…

Fix: 2.4.0+
Fix from $1,950 2021-01-05
Debian Linux HIGH 7.5
CVE-2020-25275

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain …

Fix: 2.3.13+
Fix from $1,950 2021-01-04
Debian Linux MEDIUM 6.8
CVE-2020-24386

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled par…

Fix: 2.3.13+
Fix from $1,600 2021-01-04
Debian Linux HIGH 7.5
CVE-2020-35965

decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operatio…

Fix: 4.4+
Fix from $1,950 2021-01-04
Debian Linux CRITICAL 9.8
CVE-2020-12658

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment s…

Fix: 0.8.3+
Fix from $2,300 2020-12-31
Debian Linux MEDIUM 5.3
CVE-2019-15523

An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_…

Fix: after 2.0
Fix from $1,600 2020-12-30
Debian Linux MEDIUM 6.1
CVE-2020-35738

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-…

Patch available
Fix from $1,600 2020-12-28
Debian Linux HIGH 8.1
CVE-2020-35728EPSS 13%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2020-12-27
Debian Linux HIGH 7.0
CVE-2020-28169

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account…

Fix: 2020-12-18+
Fix from $1,950 2020-12-24
Debian Linux CRITICAL 9.8
CVE-2020-35605

The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing sp…

Fix: 0.19.3+
Fix from $2,300 2020-12-21
Debian Linux HIGH 7.5
CVE-2020-35573

srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address.

Fix: 1.10+
Fix from $1,950 2020-12-20
Debian Linux HIGH 7.5
CVE-2020-35475

In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits…

Fix: 1.35.1+
Fix from $1,950 2020-12-18
Debian Linux MEDIUM 6.1
CVE-2020-35479

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, t…

Fix: 1.35.1+
Fix from $1,600 2020-12-18
Debian Linux MEDIUM 5.3
CVE-2020-35477

MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main …

Fix: 1.35.1+
Fix from $1,600 2020-12-18
Debian Linux MEDIUM 5.3
CVE-2020-35480

An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hi…

Fix: 1.35.1+
Fix from $1,600 2020-12-18
Debian Linux HIGH 8.1
CVE-2020-35490EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Fix: 2.9.10.8+
Fix from $1,950 2020-12-17
Debian Linux HIGH 8.1
CVE-2020-35491EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Fix: 2.9.10.8+
Fix from $1,950 2020-12-17
Debian Linux HIGH 7.5
CVE-2020-29361

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit li…

Fix: after 0.23.21
Fix from $1,950 2020-12-16
Debian Linux HIGH 7.5
CVE-2020-29363

An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit serve…

Fix: 0.23.22+
Fix from $1,950 2020-12-16
Debian Linux HIGH 8.8
CVE-2020-29481

An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not r…

Fix: after 4.14.0
Fix from $1,950 2020-12-15