Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2020-11018

In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound r…

Fix: after 2.0.0
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.5
CVE-2020-11017

In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. Th…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.1
CVE-2020-11082

In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has b…

Fix: 1.2.1+
Fix from $1,600 2020-05-28
Debian Linux MEDIUM 5.3
CVE-2019-20807

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby,…

Fix: 8.1.0881+
Fix from $1,600 2020-05-28
Debian Linux HIGH 7.5
CVE-2020-3811

qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

Patch available
Fix from $1,950 2020-05-26
Debian Linux MEDIUM 5.5
CVE-2020-3812

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and d…

Patch available
Fix from $1,600 2020-05-26
Debian Linux HIGH 8.2
CVE-2020-13113

An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte…

Fix: 0.6.22+
Fix from $1,950 2020-05-21
Debian Linux CRITICAL 9.1
CVE-2020-13112

An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…

Fix: 0.6.22+
Fix from $2,300 2020-05-21
Debian Linux MEDIUM 5.3
CVE-2020-8021

a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/acces…

Fix: 2.10.5+
Fix from $1,600 2020-05-19
Debian Linux HIGH 8.6
CVE-2020-8616EPSS 11%

A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, thro…

Fix: after 9.17.1
Fix from $1,950 2020-05-19
Debian Linux HIGH 7.5
CVE-2020-12662

Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NS…

Fix: 1.10.1+
Fix from $1,950 2020-05-19
Debian Linux HIGH 7.5
CVE-2020-12663

Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.

Fix: 1.10.1+
Fix from $1,950 2020-05-19
Debian Linux MEDIUM 5.9
CVE-2020-8617EPSS 93%

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfu…

Fix: after 9.17.1
Fix from $1,600 2020-05-19
Debian Linux HIGH 7.8
CVE-2018-10756

Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly exec…

Fix: 3.00+
Fix from $1,950 2020-05-15
Apt MEDIUM 5.5
CVE-2020-3810

Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafte…

Fix: 2.1.2+
Fix from $1,600 2020-05-15
Debian Linux MEDIUM 5.0
CVE-2020-0093

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local informati…

Fix: 0.6.22+
Fix from $1,600 2020-05-14
Debian Linux MEDIUM 6.1
CVE-2020-8020

A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code …

Fix: 2020-05-13+
Fix from $1,600 2020-05-13
Debian Linux MEDIUM 5.5
CVE-2020-12767

exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.

Patch available
Fix from $1,600 2020-05-09
Debian Linux MEDIUM 5.9
CVE-2020-11042

In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of…

Fix: 2.0.0+
Fix from $1,600 2020-05-07
Debian Linux MEDIUM 6.5
CVE-2020-12108

/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.

Fix: 2.1.31+
Fix from $1,600 2020-05-06
Debian Linux HIGH 7.5
CVE-2020-12672

GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

Fix: after 1.3.35
Fix from $1,950 2020-05-06
Debian Linux MEDIUM 6.5
CVE-2020-12626

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not consid…

Fix: 1.4.4+
Fix from $1,600 2020-05-04
Debian Linux MEDIUM 6.1
CVE-2020-12625

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScrip…

Fix: 1.4.4+
Fix from $1,600 2020-05-04
Debian Linux HIGH 8.1
CVE-2020-11027EPSS 14%

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to…

Fix: 3.7.33 / 3.8.33+
Fix from $1,950 2020-04-30
Debian Linux MEDIUM 6.1
CVE-2020-11029

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scriptin…

Fix: 3.7.33 / 3.8.33+
Fix from $1,600 2020-04-30
Debian Linux CRITICAL 9.8
CVE-2020-11651 KEVEPSS 97%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate…

Fix: 2019.2.4 / 3000.2+
Fix from $2,300 2020-04-30
Debian Linux MEDIUM 6.5
CVE-2020-11652 KEVEPSS 86%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth…

Fix: 2019.2.4 / 3000.2+
Fix from $1,600 2020-04-30
Debian Linux HIGH 7.5
CVE-2020-12243

In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).

Fix: 2.4.50+
Fix from $1,950 2020-04-28
Debian Linux CRITICAL 9.8
CVE-2020-12278EPSS 5%

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate …

Fix: 0.28.4+
Fix from $2,300 2020-04-27
Debian Linux CRITICAL 9.8
CVE-2020-12279EPSS 5%

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short …

Fix: 0.28.4+
Fix from $2,300 2020-04-27