Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2020-15566

An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel …

Fix: after 4.13.1
Fix from $1,600 2020-07-07
Debian Linux MEDIUM 6.5
CVE-2020-15563

An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests…

Fix: after 4.13.1
Fix from $1,600 2020-07-07
Debian Linux MEDIUM 5.5
CVE-2020-15569

PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor.

Fix: after 1.02.00
Fix from $1,600 2020-07-06
Debian Linux MEDIUM 6.1
CVE-2020-15562

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail mess…

Fix: 1.2.11 / 1.3.14+
Fix from $1,600 2020-07-06
Debian Linux HIGH 8.6
CVE-2020-8161

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory a…

Fix: 2.2.0+
Fix from $1,950 2020-07-02
Debian Linux CRITICAL 9.1
CVE-2020-15472

In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated …

Fix: after 3.2
Fix from $2,300 2020-07-01
Debian Linux HIGH 7.5
CVE-2020-15476

In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

Fix: after 3.2
Fix from $1,950 2020-07-01
Debian Linux MEDIUM 6.5
CVE-2020-15389

jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory…

Fix: after 2.3.1
Fix from $1,600 2020-06-29
Debian Linux HIGH 7.5
CVE-2020-4067

In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information bet…

Fix: 4.5.1.3+
Fix from $1,950 2020-06-29
Debian Linux MEDIUM 5.9
CVE-2020-14954

Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS"…

Fix: 1.14.4 / 20200619+
Fix from $1,600 2020-06-21
Debian Linux HIGH 7.5
CVE-2020-8184

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2020-06-19
Debian Linux MEDIUM 6.5
CVE-2020-14401

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.

Fix: 0.9.13 / 3.2.1.0+
Fix from $1,600 2020-06-17
Debian Linux HIGH 7.5
CVE-2020-14399

An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: ther…

Fix: 0.9.13+
Fix from $1,950 2020-06-17
Debian Linux HIGH 7.5
CVE-2020-14400

An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Thi…

Fix: 0.9.13+
Fix from $1,950 2020-06-17
Debian Linux MEDIUM 5.4
CVE-2020-4051

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8,…

Fix: 1.11.11 / 1.12.9+
Fix from $1,600 2020-06-15
Debian Linux HIGH 7.5
CVE-2020-14148

The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.

Fix: after 25.0
Fix from $1,950 2020-06-15
Debian Linux HIGH 7.1
CVE-2020-14152

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing exces…

Fix: 9d+
Fix from $1,950 2020-06-15
Debian Linux MEDIUM 6.5
CVE-2020-0182

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d…

Patch available
Fix from $1,600 2020-06-11
Debian Linux MEDIUM 6.1
CVE-2020-13965 KEVEPSS 77%

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am…

Fix: 1.3.12 / 1.4.5+
Fix from $1,600 2020-06-09
Debian Linux HIGH 7.8
CVE-2020-13428

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS…

Fix: 3.0.11+
Fix from $1,950 2020-06-08
Debian Linux HIGH 7.5
CVE-2020-13881

In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.

Fix: 2020.1.2+
Fix from $1,950 2020-06-06
Debian Linux HIGH 7.5
CVE-2020-13848

Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a N…

Fix: after 1.12.1
Fix from $1,950 2020-06-04
Debian Linux HIGH 7.5
CVE-2020-11080EPSS 5%

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a mal…

Fix: 1.41.0 / 10.21.0+
Fix from $1,950 2020-06-03
Debian Linux MEDIUM 5.5
CVE-2020-11089

In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_wr…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11086

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11087

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11088

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.8
CVE-2020-11039

In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and writte…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.5
CVE-2020-11019

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11038

In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instru…

Fix: 2.1.0+
Fix from $1,600 2020-05-29