Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.3
CVE-2013-2012

autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.

Fix: 21.5.8+
Fix from $1,950 2019-10-31
Debian Linux MEDIUM 6.1
CVE-2013-1951

A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web sc…

Fix: 1.19.5 / 1.20.4+
Fix from $1,600 2019-10-31
Debian Linux MEDIUM 5.4
CVE-2013-1934

A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote …

Fix: after 1.2.14
Fix from $1,600 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2013-1910

yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Tro…

Mitigation only
Fix from $2,300 2019-10-31
Overkill CRITICAL 9.8
CVE-2009-5041

overkill has buffer overflow via long player names that can corrupt data on the server machine

Fix: 0.16-14.1+
Fix from $2,300 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2009-5043

burn allows file names to escape via mishandled quotation marks

No fix yet
Fix from $2,300 2019-10-31
Debian Linux CRITICAL 9.1
CVE-2009-5042

python-docutils allows insecure usage of temporary files

Mitigation only
Fix from $2,300 2019-10-31
Debian Linux MEDIUM 6.5
CVE-2010-2490

Mumble: murmur-server has DoS due to malformed client query

Patch available
Fix from $1,600 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2019-18425

An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. Ther…

Fix: after 4.12.1
Fix from $2,300 2019-10-31
Debian Linux MEDIUM 6.8
CVE-2019-18424

An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…

Fix: after 4.12.1
Fix from $1,600 2019-10-31
Debian Linux HIGH 8.8
CVE-2019-18423

An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->ma…

Fix: after 4.12.1
Fix from $1,950 2019-10-31
Debian Linux HIGH 8.8
CVE-2019-18422

An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous…

Fix: after 4.12.1
Fix from $1,950 2019-10-31
Debian Linux HIGH 7.5
CVE-2019-18421

An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable pr…

Fix: after 4.12.1
Fix from $1,950 2019-10-31
Debian Linux MEDIUM 6.5
CVE-2019-18420

An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercal…

Fix: after 4.12.1
Fix from $1,600 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2010-0748

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr a…

Fix: 1.92+
Fix from $2,300 2019-10-30
Debian Linux MEDIUM 5.3
CVE-2010-0749

Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.

Fix: 1.92+
Fix from $1,600 2019-10-30
Debian Linux HIGH 8.2
CVE-2011-1408

ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

Fix: 3.20110608+
Fix from $1,950 2019-10-29
Debian Linux HIGH 7.5
CVE-2019-18602

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the netw…

Fix: 1.6.24 / 1.8.5+
Fix from $1,950 2019-10-29
Debian Linux MEDIUM 5.9
CVE-2019-18603

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables…

Fix: 1.6.24 / 1.8.5+
Fix from $1,600 2019-10-29
Debian Linux HIGH 7.5
CVE-2011-4931

gpw generates shorter passwords than required

No fix yet
Fix from $1,950 2019-10-29
Debian Linux HIGH 7.5
CVE-2009-3723

asterisk allows calls on prohibited networks

Fix: 1.6.1.8+
Fix from $1,950 2019-10-29
Debian Linux MEDIUM 5.5
CVE-2010-3373

paxtest handles temporary files insecurely

No fix yet
Fix from $1,600 2019-10-29
Debian Linux HIGH 7.5
CVE-2019-18408

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED si…

Fix: 3.4.0+
Fix from $1,950 2019-10-24
Debian Linux HIGH 7.8
CVE-2019-18218

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (…

Fix: after 5.37
Fix from $1,950 2019-10-21
Debian Linux MEDIUM 6.8
CVE-2019-2949

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u2…

Fix: after 11.50.2
Fix from $1,600 2019-10-16
Debian Linux MEDIUM 5.9
CVE-2019-2958

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u…

Fix: after 11.50.2
Fix from $1,600 2019-10-16
Debian Linux CRITICAL 9.8
CVE-2019-17545

GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

Fix: after 3.0.1
Fix from $2,300 2019-10-14
Debian Linux CRITICAL 9.8
CVE-2019-17539

In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no va…

Fix: 3.4.7 / 4.0.5+
Fix from $2,300 2019-10-14
Debian Linux HIGH 8.8
CVE-2019-17540

ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.

Fix: 6.9.10-55 / 7.0.8-54+
Fix from $1,950 2019-10-14
Debian Linux HIGH 8.2
CVE-2019-17533

Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninit…

Patch available
Fix from $1,950 2019-10-13