Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2020-25074EPSS 7%

The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload …

Fix: after 1.9.10
Fix from $2,300 2020-11-10
Debian Linux HIGH 7.1
CVE-2017-18926

raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for t…

Patch available
Fix from $1,950 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2020-25592EPSS 58%

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Debian Linux MEDIUM 6.5
CVE-2020-27617

eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data…

Patch available
Fix from $1,600 2020-11-06
Debian Linux MEDIUM 5.5
CVE-2020-17490

The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,600 2020-11-06
Debian Linux MEDIUM 6.5
CVE-2020-28241

libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.

Fix: 1.4.3+
Fix from $1,600 2020-11-06
Debian Linux MEDIUM 6.3
CVE-2020-28049

An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged…

Fix: 0.19.0+
Fix from $1,600 2020-11-04
Debian Linux HIGH 7.5
CVE-2020-8037

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

Fix: 10.14.6 / 10.15.7+
Fix from $1,950 2020-11-04
Debian Linux HIGH 7.0
CVE-2020-15238

Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume…

Fix: 2.1.4+
Fix from $1,950 2020-10-27
Debian Linux HIGH 7.8
CVE-2020-27671

An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data le…

Fix: after 4.14.0
Fix from $1,950 2020-10-22
Debian Linux HIGH 7.5
CVE-2020-27638

receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

Fix: 21.0+
Fix from $1,950 2020-10-22
Debian Linux HIGH 8.6
CVE-2020-27153

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a …

Fix: 5.55+
Fix from $1,950 2020-10-15
Debian Linux HIGH 7.8
CVE-2020-0423

In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in t…

Mitigation only
Fix from $1,950 2020-10-14
Debian Linux MEDIUM 5.5
CVE-2020-15250

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste…

Fix: 3.1.1 / 4.13.1+
Fix from $1,600 2020-10-12
Debian Linux MEDIUM 6.1
CVE-2020-26870

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree…

Fix: 2.0.17 / 21.1.0.00.01+
Fix from $1,600 2020-10-07
Debian Linux CRITICAL 9.8
CVE-2020-11800EPSS 9%

Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

Fix: 3.0.31+
Fix from $2,300 2020-10-07
Debian Linux HIGH 7.5
CVE-2020-15598

Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are…

Fix: after 3.0.4
Fix from $1,950 2020-10-06
Debian Linux MEDIUM 5.5
CVE-2020-26571

The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.

Fix: after 0.20.0
Fix from $1,600 2020-10-06
Debian Linux MEDIUM 5.7
CVE-2019-14558

Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Seri…

Mitigation only
Fix from $1,600 2020-10-05
Debian Linux MEDIUM 5.5
CVE-2020-26519

Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.

Fix: 1.18.0+
Fix from $1,600 2020-10-02
Debian Linux CRITICAL 9.8
CVE-2020-15227EPSS 34%

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…

Fix: 2.0.19 / 2.1.13+
Fix from $2,300 2020-10-01
Debian Linux HIGH 8.1
CVE-2020-26117

In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificate…

Fix: 1.11.0+
Fix from $1,950 2020-09-27
Debian Linux MEDIUM 5.3
CVE-2020-25625

hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.

Patch available
Fix from $1,600 2020-09-25
Debian Linux MEDIUM 5.0
CVE-2020-25085

QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZ…

Patch available
Fix from $1,600 2020-09-25
Debian Linux MEDIUM 5.5
CVE-2020-25601

An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event chan…

Fix: after 4.14.0
Fix from $1,600 2020-09-23
Debian Linux HIGH 8.1
CVE-2020-24750EPSS 7%

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcompon…

Fix: 2.6.7.5 / 2.9.10.6+
Fix from $1,950 2020-09-17
Debian Linux MEDIUM 5.5
CVE-2020-0427

In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no …

Patch available
Fix from $1,600 2020-09-17
Debian Linux MEDIUM 6.5
CVE-2020-8927

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression r…

Fix: 1.0.8 / 7.0.9+
Fix from $1,600 2020-09-15
Debian Linux CRITICAL 9.8
CVE-2020-24660

An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Host…

Fix: after 2.0.8
Fix from $2,300 2020-09-14