Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2019-16786

Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it wou…

Fix: 1.3.1+
Fix from $1,950 2019-12-20
Debian Linux CRITICAL 9.8
CVE-2012-6094

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

Fix: 1.5.4-1.1+
Fix from $2,300 2019-12-20
Debian Linux HIGH 7.5
CVE-2012-6111

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

Mitigation only
Fix from $1,950 2019-12-20
Debian Linux HIGH 7.8
CVE-2012-3409

ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

Fix: 99+
Fix from $1,950 2019-12-20
Debian Linux MEDIUM 6.5
CVE-2012-5639EPSS 6%

LibreOffice and OpenOffice automatically open embedded content

No fix yet
Fix from $1,600 2019-12-20
Debian Linux MEDIUM 5.9
CVE-2015-8313

GnuTLS incorrectly validates the first byte of padding in CBC modes

Fix: after 2.12.24
Fix from $1,600 2019-12-20
Debian Linux HIGH 7.5
CVE-2019-19906EPSS 8%

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP pa…

Patch available
Fix from $1,950 2019-12-19
Debian Linux MEDIUM 6.1
CVE-2012-2237

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary we…

Fix: 1.4.3 / 1.5.2+
Fix from $1,600 2019-12-17
Debian Linux MEDIUM 6.5
CVE-2019-19830

_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.

Fix: 3.2.7+
Fix from $1,600 2019-12-17
Debian Linux HIGH 7.5
CVE-2019-19331

knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might…

Fix: 4.3.0+
Fix from $1,950 2019-12-16
Debian Linux MEDIUM 6.5
CVE-2019-19783

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or cert…

Fix: 2.5.15 / 3.0.13+
Fix from $1,600 2019-12-16
Debian Linux CRITICAL 9.8
CVE-2014-8650

python-requests-Kerberos through 0.5 does not handle mutual authentication

Fix: after 0.5
Fix from $2,300 2019-12-15
Debian Linux MEDIUM 6.5
CVE-2014-8561

imagemagick 6.8.9.6 has remote DOS via infinite loop

Patch available
Fix from $1,600 2019-12-15
Debian Linux MEDIUM 6.1
CVE-2014-4913

ZF2014-03 has a potential cross site scripting vector in multiple view helpers

Fix: 2.2.7 / 2.3.1+
Fix from $1,600 2019-12-15
Duplicity HIGH 7.5
CVE-2014-3495

duplicity 0.6.24 has improper verification of SSL certificates

No fix yet
Fix from $1,950 2019-12-13
Debian Linux CRITICAL 9.3
CVE-2019-18345

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied…

Fix: after 1.1.8
Fix from $2,300 2019-12-12
Debian Linux HIGH 8.1
CVE-2019-17358

Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An auth…

Fix: after 1.2.7
Fix from $1,950 2019-12-12
Debian Linux CRITICAL 9.8
CVE-2019-19725

sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

Fix: after 12.2.0
Fix from $2,300 2019-12-11
Debian Linux MEDIUM 6.1
CVE-2013-7371

node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)

Fix: 2.8.2+
Fix from $1,600 2019-12-11
Debian Linux HIGH 7.3
CVE-2013-4245

Orca has arbitrary code execution due to insecure Python module load

Mitigation only
Fix from $1,950 2019-12-11
Debian Linux MEDIUM 6.1
CVE-2013-4158

smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)

Fix: 2.6.9+
Fix from $1,600 2019-12-11
Debian Linux MEDIUM 6.1
CVE-2019-19709

MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-…

Fix: after 1.33.1
Fix from $1,600 2019-12-11
Debian Linux HIGH 7.5
CVE-2019-5815

Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted X…

Fix: 1.1.33+
Fix from $1,950 2019-12-11
Debian Linux CRITICAL 9.8
CVE-2012-1577

lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.

Mitigation only
Fix from $2,300 2019-12-10
Debian Linux HIGH 7.5
CVE-2013-4133

kde-workspace before 4.10.5 has a memory leak in plasma desktop

Fix: 4.10.5+
Fix from $1,950 2019-12-10
Debian Linux MEDIUM 6.1
CVE-2016-1000108

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the pr…

Fix: 2.0.4+
Fix from $1,600 2019-12-10
Debian Linux MEDIUM 5.5
CVE-2013-4184

Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks

Fix: 1.224+
Fix from $1,600 2019-12-10
Debian Linux HIGH 7.8
CVE-2019-19630

HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a cr…

No fix yet
Fix from $1,950 2019-12-08
Debian Linux HIGH 7.4
CVE-2012-2130

A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RS…

Fix: after 1.1.1
Fix from $1,950 2019-12-06
Debian Linux CRITICAL 9.8
CVE-2019-19617

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.ph…

Fix: 4.9.2+
Fix from $2,300 2019-12-06