Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2019-17531EPSS 5%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-12
Debian Linux HIGH 7.8
CVE-2019-2215 KEVEPSS 44%

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit thi…

Patch available
Fix from $1,950 2019-10-11
Debian Linux CRITICAL 9.8
CVE-2019-17455

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations,…

Fix: after 1.5
Fix from $2,300 2019-10-10
Debian Linux MEDIUM 6.5
CVE-2019-17402

Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in cr…

Mitigation only
Fix from $1,600 2019-10-09
Debian Linux CRITICAL 9.1
CVE-2019-17362

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 seque…

Fix: after 1.18.2
Fix from $2,300 2019-10-09
Debian Linux MEDIUM 5.5
CVE-2019-17349

An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreE…

Fix: after 4.12.1
Fix from $1,600 2019-10-08
Debian Linux HIGH 8.8
CVE-2019-17340

An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-table transfe…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux HIGH 8.8
CVE-2019-17346

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatib…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux HIGH 7.8
CVE-2019-17341

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-wri…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux HIGH 7.8
CVE-2019-17347

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can mani…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux HIGH 7.0
CVE-2019-17342

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a race con…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux MEDIUM 6.8
CVE-2019-17343

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect …

Fix: after 4.11.2
Fix from $1,600 2019-10-08
Debian Linux MEDIUM 6.5
CVE-2019-17344

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that…

Fix: after 4.11.2
Fix from $1,600 2019-10-08
Debian Linux MEDIUM 6.5
CVE-2019-17345

An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU o…

Fix: after 4.11.2
Fix from $1,600 2019-10-08
Debian Linux MEDIUM 6.5
CVE-2019-17348

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an incompatibility between Proce…

Fix: after 4.11.2
Fix from $1,600 2019-10-08
Debian Linux MEDIUM 5.5
CVE-2019-17350

An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchan…

Fix: after 4.12.1
Fix from $1,600 2019-10-08
Debian Linux CRITICAL 9.8
CVE-2019-17041

An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages.…

Patch available
Fix from $2,300 2019-10-07
Debian Linux MEDIUM 5.3
CVE-2019-15165

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

Fix: 1.9.1+
Fix from $1,600 2019-10-03
Debian Linux HIGH 7.5
CVE-2019-15166

lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14470

The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14880EPSS 5%

The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

Fix: after 15.0.1
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14881

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16227EPSS 7%

The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16228

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16230

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16451

The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14461

The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14464

The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14466

The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14467

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03