Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2018-14468

The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

Fix: after 15.0.1
Fix from $1,950 2019-10-03
Debian Linux CRITICAL 9.8
CVE-2019-16942EPSS 6%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Debian Linux CRITICAL 9.8
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Debian Linux HIGH 8.8
CVE-2019-16993

In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa…

Fix: after 3.1.7
Fix from $1,950 2019-09-30
Debian Linux HIGH 7.5
CVE-2019-16869EPSS 8%

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP …

Fix: 4.1.42+
Fix from $1,950 2019-09-26
Debian Linux MEDIUM 6.1
CVE-2017-18635

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the …

Fix: 0.6.2+
Fix from $1,600 2019-09-25
Debian Linux CRITICAL 9.8
CVE-2019-15941

OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat…

Fix: after 2.0.5
Fix from $2,300 2019-09-25
Debian Linux HIGH 7.5
CVE-2019-5094

An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause …

Fix: after 1.45.3
Fix from $1,950 2019-09-24
Debian Linux HIGH 7.8
CVE-2019-16729

pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation …

Fix: 1.0.7-1+
Fix from $1,950 2019-09-24
Debian Linux MEDIUM 6.1
CVE-2019-16728

DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.

Fix: 2.0.1+
Fix from $1,600 2019-09-24
Debian Linux MEDIUM 6.5
CVE-2019-16710

ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.

Patch available
Fix from $1,600 2019-09-23
Debian Linux MEDIUM 6.5
CVE-2019-16711

ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.

Patch available
Fix from $1,600 2019-09-23
Debian Linux MEDIUM 5.3
CVE-2019-16394EPSS 8%

SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exis…

Fix: 3.1.11 / 3.2.5+
Fix from $1,600 2019-09-17
Debian Linux CRITICAL 9.8
CVE-2019-16378

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect …

Fix: after 1.3.2
Fix from $2,300 2019-09-17
Debian Linux MEDIUM 6.5
CVE-2018-21015

AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and applicat…

No fix yet
Fix from $1,600 2019-09-16
Debian Linux MEDIUM 6.5
CVE-2018-21016

audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-re…

No fix yet
Fix from $1,600 2019-09-16
Debian Linux MEDIUM 6.5
CVE-2019-16275

hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address valida…

Fix: after 2.9
Fix from $1,600 2019-09-12
Debian Linux HIGH 7.5
CVE-2016-10937

IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

Fix: after 2.6.12
Fix from $1,950 2019-09-08
Debian Linux CRITICAL 9.8
CVE-2019-15846EPSS 36%

Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

Fix: 4.92.2+
Fix from $2,300 2019-09-06
Debian Linux MEDIUM 6.4
CVE-2019-15946

OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.

Fix: after 0.19.0
Fix from $1,600 2019-09-05
Debian Linux MEDIUM 6.4
CVE-2019-15945

OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.

Fix: after 0.19.0
Fix from $1,600 2019-09-05
Debian Linux MEDIUM 5.9
CVE-2019-15939

An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modules/objdetect/src/hog.cpp.

Fix: after 4.1.0
Fix from $1,600 2019-09-05
Debian Linux HIGH 8.8
CVE-2018-21010

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

Fix: 2.3.1+
Fix from $1,950 2019-09-05
Debian Linux HIGH 7.5
CVE-2019-15892EPSS 6%

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to tr…

Fix: 6.0.4 / 6.2.1+
Fix from $1,950 2019-09-03
Debian Linux HIGH 8.8
CVE-2015-9381

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.

Fix: 2.6.1+
Fix from $1,950 2019-09-03
Debian Linux MEDIUM 6.5
CVE-2015-9382

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face…

Fix: 2.6.1+
Fix from $1,600 2019-09-03
Debian Linux MEDIUM 6.5
CVE-2015-9383

FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.

Fix: 2.6.2+
Fix from $1,600 2019-09-03
Debian Linux HIGH 7.8
CVE-2019-14533

The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14776

A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14777

The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

Patch available
Fix from $1,950 2019-08-29