Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.3
CVE-2020-1765

An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicke…

Fix: after 7.0.13
Fix from $1,600 2020-01-10
Debian Linux HIGH 7.8
CVE-2019-20373

LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support fo…

Fix: after 2.18.06
Fix from $1,950 2020-01-09
Debian Linux HIGH 8.8
CVE-2020-5504EPSS 39%

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of…

Fix: 4.9.4 / 5.0.1+
Fix from $1,950 2020-01-09
Debian Linux CRITICAL 9.1
CVE-2019-20367

nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

Fix: 0.10.0+
Fix from $2,300 2020-01-08
Debian Linux MEDIUM 5.5
CVE-2020-0009

In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalati…

Patch available
Fix from $1,600 2020-01-08
Debian Linux HIGH 7.5
CVE-2019-18625

An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil serve…

Patch available
Fix from $1,950 2020-01-06
Debian Linux CRITICAL 9.1
CVE-2019-18792

An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet…

Fix: 4.1.6+
Fix from $2,300 2020-01-06
Debian Linux CRITICAL 9.8
CVE-2019-20330EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-01-03
Debian Linux HIGH 7.5
CVE-2014-8182

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv bac…

Patch available
Fix from $1,950 2020-01-02
Debian Linux MEDIUM 5.9
CVE-2014-6275

FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages a…

Fix: 5.3.2+
Fix from $1,600 2020-01-02
Debian Linux MEDIUM 5.5
CVE-2019-20208

dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.

Fix: after 0.8.0
Fix from $1,600 2020-01-02
Debian Linux HIGH 7.5
CVE-2013-4357

The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

Fix: 2.14+
Fix from $1,950 2019-12-31
Debian Linux MEDIUM 6.5
CVE-2019-14466

The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per…

Patch available
Fix from $1,600 2019-12-31
Debian Linux MEDIUM 5.5
CVE-2019-20170

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_D…

No fix yet
Fix from $1,600 2019-12-31
Debian Linux MEDIUM 5.5
CVE-2019-20171

An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst…

Fix: after 0.8.0
Fix from $1,600 2019-12-31
Debian Linux MEDIUM 5.5
CVE-2019-20161

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_Waterm…

No fix yet
Fix from $1,600 2019-12-31
Debian Linux MEDIUM 5.5
CVE-2019-20162

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_e…

No fix yet
Fix from $1,600 2019-12-31
Debian Linux MEDIUM 5.5
CVE-2019-20163

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_writ…

No fix yet
Fix from $1,600 2019-12-31
Debian Linux MEDIUM 5.5
CVE-2019-20165

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in…

No fix yet
Fix from $1,600 2019-12-31
Debian Linux HIGH 7.8
CVE-2013-2016

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the vi…

Fix: after 1.4.2
Fix from $1,950 2019-12-30
Debian Linux MEDIUM 5.5
CVE-2012-5476

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the adm…

Mitigation only
Fix from $1,600 2019-12-30
Debian Linux HIGH 8.2
CVE-2019-16789

In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the fr…

Fix: after 1.4.0
Fix from $1,950 2019-12-26
Debian Linux HIGH 7.5
CVE-2019-19956EPSS 6%

xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

Fix: 2.9.10+
Fix from $1,950 2019-12-24
Debian Linux CRITICAL 9.8
CVE-2019-19950

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.8
CVE-2019-19951

In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.1
CVE-2019-19949

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_pr…

Fix: 6.9.10-43 / 7.0.8-43+
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.1
CVE-2019-19953

In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.

Patch available
Fix from $2,300 2019-12-24
Debian Lan Config HIGH 7.8
CVE-2019-3467

Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive A…

Fix: 0.26 / 2.11.10+
Fix from $1,950 2019-12-23
Debian Linux MEDIUM 5.5
CVE-2019-18388

A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed comman…

Fix: after 0.8.0
Fix from $1,600 2019-12-23
Debian Linux HIGH 7.5
CVE-2019-16785

Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fiel…

Fix: after 1.3.1
Fix from $1,950 2019-12-20