Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2020-12268

jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

Fix: 0.18+
Fix from $2,300 2020-04-27
Debian Linux MEDIUM 6.1
CVE-2020-12137

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks a…

Fix: 2.1.30+
Fix from $1,600 2020-04-24
Debian Linux CRITICAL 9.8
CVE-2020-11945EPSS 27%

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that ar…

Fix: 4.11 / 5.0.2+
Fix from $2,300 2020-04-23
Debian Linux CRITICAL 9.8
CVE-2019-12519EPSS 7%

An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function …

Fix: after 5.0.1
Fix from $2,300 2020-04-15
Debian Linux CRITICAL 9.8
CVE-2019-12524

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid…

Fix: after 4.7
Fix from $2,300 2020-04-15
Debian Linux CRITICAL 9.8
CVE-2020-11729

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity…

Fix: after 0.60
Fix from $2,300 2020-04-15
Debian Linux HIGH 7.5
CVE-2020-11728

An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session ke…

Fix: after 0.60
Fix from $1,950 2020-04-15
Debian Linux MEDIUM 5.5
CVE-2020-11740

An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about o…

Fix: after 4.13.0
Fix from $1,600 2020-04-14
Debian Linux HIGH 7.5
CVE-2020-11724

An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.ca…

Fix: 1.15.8.4+
Fix from $1,950 2020-04-12
Debian Linux HIGH 7.5
CVE-2020-11653

An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a …

Fix: 6.0.6 / 6.2.3+
Fix from $1,950 2020-04-08
Debian Linux HIGH 8.1
CVE-2020-11619

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.ao…

Fix: 2.9.10.4+
Fix from $1,950 2020-04-07
Debian Linux HIGH 8.1
CVE-2020-11620EPSS 6%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jel…

Fix: 2.9.10.4+
Fix from $1,950 2020-04-07
Debian Linux HIGH 7.5
CVE-2020-11612EPSS 9%

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send …

Fix: 4.1.46+
Fix from $1,950 2020-04-07
Debian Linux HIGH 7.8
CVE-2019-14868

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypas…

Fix: 10.15.5+
Fix from $1,950 2020-04-02
Debian Linux HIGH 8.8
CVE-2020-11100EPSS 61%

In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a…

Fix: 2.1.4+
Fix from $1,950 2020-04-02
Debian Linux HIGH 7.8
CVE-2020-5291

Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2`…

Fix: 0.4.1+
Fix from $1,950 2020-03-31
Debian Linux CRITICAL 9.8
CVE-2020-10595

pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library…

Fix: 4.9+
Fix from $2,300 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11111

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* …

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11112

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11113EPSS 6%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 7.5
CVE-2020-1772

It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users…

Fix: after 7.0.15
Fix from $1,950 2020-03-27
Debian Linux HIGH 8.8
CVE-2020-10969

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPan…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $1,950 2020-03-26
Debian Linux HIGH 8.8
CVE-2020-10968

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.pro…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-26
Debian Linux CRITICAL 9.8
CVE-2020-6072

An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels …

No fix yet
Fix from $2,300 2020-03-24
Debian Linux HIGH 7.5
CVE-2020-6071

An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compr…

No fix yet
Fix from $1,950 2020-03-24
Debian Linux HIGH 7.5
CVE-2020-6073

An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA …

No fix yet
Fix from $1,950 2020-03-24
Debian Linux HIGH 7.5
CVE-2020-6077

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages…

No fix yet
Fix from $1,950 2020-03-24
Debian Linux HIGH 7.5
CVE-2020-6078

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages…

No fix yet
Fix from $1,950 2020-03-24
Debian Linux HIGH 7.5
CVE-2020-6079

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors wh…

No fix yet
Fix from $1,950 2020-03-24
Debian Linux HIGH 7.5
CVE-2020-6080

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors wh…

No fix yet
Fix from $1,950 2020-03-24