Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2020-29483

An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest viol…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.0
CVE-2020-29482

An issue was discovered in Xen through 4.14.x. A guest may access xenstore paths via absolute paths containing a full pathname, or via a relative pat…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.0
CVE-2020-29484

An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore mes…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.0
CVE-2020-29486

An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node owne…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 5.5
CVE-2020-29485

An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest …

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux HIGH 8.8
CVE-2020-29479

An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for t…

Fix: after 4.14.0
Fix from $1,950 2020-12-15
Debian Linux MEDIUM 6.5
CVE-2020-29568

An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If t…

Fix: after 4.14.1
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.2
CVE-2020-29570

An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the contro…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.2
CVE-2020-29571

An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the …

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 5.5
CVE-2020-29566

An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. T…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux HIGH 7.5
CVE-2020-8231

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

Fix: 1.0.1.1 / 8.2.12+
Fix from $1,950 2020-12-14
Debian Linux HIGH 7.5
CVE-2020-8285EPSS 10%

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

Fix: 7.74.0+
Fix from $1,950 2020-12-14
Debian Linux MEDIUM 5.3
CVE-2020-35176

In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to on…

Fix: after 7.8
Fix from $1,600 2020-12-12
Debian Linux CRITICAL 9.8
CVE-2020-7788

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pol…

Fix: 1.3.6+
Fix from $2,300 2020-12-11
Advanced Package Tool MEDIUM 5.7
CVE-2020-27350

APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc…

Fix: 1.2.32ubuntu0.2 / 1.6.12ubuntu0.2+
Fix from $1,600 2020-12-10
Debian Linux MEDIUM 5.5
CVE-2020-16587

A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.…

Patch available
Fix from $1,600 2020-12-09
Debian Linux MEDIUM 5.5
CVE-2020-16588

A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of s…

Patch available
Fix from $1,600 2020-12-09
Debian Linux MEDIUM 5.5
CVE-2020-16589

A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial o…

Patch available
Fix from $1,600 2020-12-09
Debian Linux MEDIUM 6.0
CVE-2020-27821

A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds w…

Fix: 5.2.0+
Fix from $1,600 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-25674

WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buf…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-25676

In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in …

Fix: 6.9.10-69 / 7.0.9-0+
Fix from $1,600 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-27750

A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a crafted file that is processed…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-25665

The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 2…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-28935

NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that wou…

Fix: 1.13.0 / 4.3.4+
Fix from $1,600 2020-12-07
Debian Linux CRITICAL 9.8
CVE-2020-29600

In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/…

Fix: after 7.7
Fix from $2,300 2020-12-07
Debian Linux HIGH 7.8
CVE-2020-29599EPSS 8%

ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF…

Fix: 6.9.11-40 / 7.0.10-40+
Fix from $1,950 2020-12-07
Debian Linux HIGH 7.8
CVE-2020-27766

A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger unde…

Fix: 6.9.10-69 / 7.0.8-69+
Fix from $1,950 2020-12-04
Debian Linux MEDIUM 5.5
CVE-2020-27770

Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to …

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-04
Debian Linux MEDIUM 6.1
CVE-2020-29565

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of v…

Fix: 15.3.2 / 16.2.1+
Fix from $1,600 2020-12-04
Debian Linux MEDIUM 5.5
CVE-2020-28916

hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

Patch available
Fix from $1,600 2020-12-04