Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2014-6262EPSS 7%

Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attacker…

Fix: 4.2.5+
Fix from $1,950 2020-02-12
Debian Linux HIGH 8.1
CVE-2020-5529

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can …

Fix: 2.37.0+
Fix from $1,950 2020-02-11
Debian Linux CRITICAL 9.8
CVE-2020-8840EPSS 27%

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC…

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-02-10
Debian Linux MEDIUM 5.6
CVE-2020-8608

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.

Patch available
Fix from $1,600 2020-02-06
Debian Linux HIGH 8.8
CVE-2020-5208

It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lea…

Patch available
Fix from $1,950 2020-02-05
Debian Linux HIGH 7.5
CVE-2020-8449EPSS 8%

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access …

Fix: 4.10+
Fix from $1,950 2020-02-04
Debian Linux CRITICAL 9.8
CVE-2020-8597EPSS 20%

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

Fix: 03.04.10+
Fix from $2,300 2020-02-03
Debian Linux CRITICAL 9.1
CVE-2019-20444EPSS 9%

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incor…

Fix: 4.1.44+
Fix from $2,300 2020-01-29
Debian Linux CRITICAL 9.1
CVE-2019-20445EPSS 13%

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-En…

Fix: 4.1.44+
Fix from $2,300 2020-01-29
Debian Linux HIGH 7.8
CVE-2019-18634EPSS 19%

In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwf…

Fix: 1.8.26+
Fix from $1,950 2020-01-29
Debian Linux CRITICAL 9.8
CVE-2020-7247 KEVEPSS 99%

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as…

Patch available
Fix from $2,300 2020-01-29
Debian Linux CRITICAL 9.8
CVE-2015-8011EPSS 5%

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (da…

Fix: 0.8.0+
Fix from $2,300 2020-01-28
Debian Linux HIGH 8.8
CVE-2020-8112

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different…

No fix yet
Fix from $1,950 2020-01-28
Debian Linux CRITICAL 9.8
CVE-2020-8086

The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f…

Fix: after 2020-01-27
Fix from $2,300 2020-01-28
Debian Linux MEDIUM 5.5
CVE-2020-0549

Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure…

Mitigation only
Fix from $1,600 2020-01-28
Debian Linux HIGH 7.5
CVE-2015-0294

GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

Fix: 3.3.13+
Fix from $1,950 2020-01-27
Debian Linux MEDIUM 5.5
CVE-2020-8003

A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture al…

Fix: after 0.8.1
Fix from $1,600 2020-01-27
Debian Linux MEDIUM 5.5
CVE-2020-8002

A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via commands that attempt…

Fix: after 0.8.1
Fix from $1,600 2020-01-27
Debian Linux CRITICAL 9.8
CVE-2014-4172EPSS 6%

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.…

Fix: 1.0.2 / 1.3.3+
Fix from $2,300 2020-01-24
Debian Linux HIGH 7.5
CVE-2019-16792

Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Lengt…

Fix: after 1.3.1
Fix from $1,950 2020-01-22
Debian Linux HIGH 7.5
CVE-2019-20387

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of …

Fix: 0.7.6+
Fix from $1,950 2020-01-21
Debian Linux HIGH 7.5
CVE-2019-20388

xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.

Patch available
Fix from $1,950 2020-01-21
Debian Linux HIGH 8.1
CVE-2020-7040

storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege …

Fix: after 3.5
Fix from $1,950 2020-01-21
Debian Linux MEDIUM 5.5
CVE-2020-5202

apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool…

Fix: after 3.3
Fix from $1,600 2020-01-21
Debian Linux CRITICAL 9.8
CVE-2019-17361EPSS 15%

In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticat…

Fix: after 2019.2.0
Fix from $2,300 2020-01-17
Debian Linux MEDIUM 5.6
CVE-2020-7039

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a h…

Patch available
Fix from $1,600 2020-01-16
Debian Linux MEDIUM 6.1
CVE-2020-7106

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and us…

Fix: 1.2.9+
Fix from $1,600 2020-01-16
Debian Linux HIGH 7.5
CVE-2015-5230EPSS 9%

The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of se…

Fix: 3.4.6+
Fix from $1,950 2020-01-15
Debian Linux HIGH 7.5
CVE-2019-19728

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.

Fix: 18.08.9 / 19.05.5+
Fix from $1,950 2020-01-13
Debian Linux MEDIUM 6.1
CVE-2020-1766

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious java…

Fix: after 7.0.13
Fix from $1,600 2020-01-10