Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2020-10938EPSS 5%

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

Fix: 1.3.35+
Fix from $2,300 2020-03-24
Debian Linux MEDIUM 5.3
CVE-2020-9359

KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.

Fix: 1.10.0 / 19.12.3+
Fix from $1,600 2020-03-24
Debian Linux MEDIUM 6.5
CVE-2020-8866EPSS 10%

This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat…

Fix: 2.0.20+
Fix from $1,600 2020-03-23
Debian Linux MEDIUM 6.3
CVE-2020-8865EPSS 7%

This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentica…

Mitigation only
Fix from $1,600 2020-03-23
Debian Linux CRITICAL 9.8
CVE-2020-9760

An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buff…

Fix: 2.7.1+
Fix from $2,300 2020-03-23
Debian Linux HIGH 8.0
CVE-2020-10802

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly esca…

Fix: 4.9.5 / 5.0.2+
Fix from $1,950 2020-03-22
Debian Linux MEDIUM 5.4
CVE-2020-10803

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS…

Fix: 4.9.5 / 5.0.2+
Fix from $1,600 2020-03-22
Debian Linux MEDIUM 6.1
CVE-2019-18860EPSS 6%

Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.

Fix: 4.9+
Fix from $1,600 2020-03-20
Debian Linux HIGH 8.8
CVE-2020-10672

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.trans…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-18
Debian Linux HIGH 8.8
CVE-2020-10673EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.type…

Fix: 2.6.7.4 / 2.9.10.4+
Fix from $1,950 2020-03-18
Debian Linux MEDIUM 6.5
CVE-2019-12921EPSS 8%

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of Translate…

Fix: 1.3.32+
Fix from $1,600 2020-03-18
Debian Linux HIGH 7.8
CVE-2019-20326

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.…

Fix: 2.4.5 / 3.8.3+
Fix from $1,950 2020-03-16
Debian Linux HIGH 7.5
CVE-2020-0034

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information …

Mitigation only
Fix from $1,950 2020-03-10
Debian Linux HIGH 7.7
CVE-2020-5258

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to in…

Fix: 1.11.10 / 1.12.8+
Fix from $1,950 2020-03-10
Debian Linux MEDIUM 5.5
CVE-2012-1096

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when ad…

Fix: after 0.9.0
Fix from $1,600 2020-03-10
Debian Linux CRITICAL 9.8
CVE-2020-10232

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaf…

Fix: after 4.8.0
Fix from $2,300 2020-03-09
Debian Linux MEDIUM 6.5
CVE-2019-20503

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

Fix: 0.9.4.0+
Fix from $1,600 2020-03-06
Debian Linux HIGH 7.8
CVE-2020-9549

In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document.

Fix: after 0.19
Fix from $1,950 2020-03-02
Debian Linux HIGH 7.5
CVE-2019-10064

hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, w…

Fix: 2.6+
Fix from $1,950 2020-02-28
Debian Linux HIGH 7.5
CVE-2020-9274EPSS 6%

An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup…

Fix: 1.0.50+
Fix from $1,950 2020-02-26
Debian Linux HIGH 7.5
CVE-2015-9542

add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based b…

Patch available
Fix from $1,950 2020-02-24
Debian Linux CRITICAL 9.8
CVE-2020-9355

danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.

Fix: 1.2.11+
Fix from $2,300 2020-02-23
X11 Common HIGH 7.8
CVE-2012-1093

The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during pac…

Fix: 1+
Fix from $1,950 2020-02-21
Debian Linux MEDIUM 5.5
CVE-2012-0844

Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

Fix: after 2.8
Fix from $1,600 2020-02-21
Debian Linux HIGH 8.8
CVE-2020-9273EPSS 12%

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool i…

Fix: 3.0+
Fix from $1,950 2020-02-20
Debian Linux MEDIUM 6.1
CVE-2019-20479

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

Fix: 2.4.1+
Fix from $1,600 2020-02-20
Debian Linux HIGH 7.5
CVE-2020-6062EPSS 6%

An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST reques…

No fix yet
Fix from $1,950 2020-02-19
Debian Linux HIGH 8.8
CVE-2015-0258

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticate…

Fix: 2.1+
Fix from $1,950 2020-02-17
Debian Linux MEDIUM 6.1
CVE-2019-10785

dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xm…

Fix: 1.11.9 / 1.12.7+
Fix from $1,600 2020-02-13
Debian Linux HIGH 7.0
CVE-2019-19921

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an…

Fix: after 0.1.1
Fix from $1,950 2020-02-12