Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2019-14778

The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14970

A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a cra…

Patch available
Fix from $1,950 2019-08-29
Debian Linux MEDIUM 5.5
CVE-2019-14534

In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial o…

Patch available
Fix from $1,600 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14437

The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap…

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14438

A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a…

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14498

A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a…

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14535

A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered…

Patch available
Fix from $1,950 2019-08-29
Debian Linux CRITICAL 9.8
CVE-2019-11500EPSS 63%

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs bec…

Fix: 0.5.7.2 / 2.2.36.4+
Fix from $2,300 2019-08-29
Debian Linux CRITICAL 9.8
CVE-2019-13273

In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET req…

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13451

In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13452

In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13455

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in ackno…

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13484

In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13485

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter …

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13486

In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux MEDIUM 6.1
CVE-2019-13274

In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.

Fix: after 4.3.28
Fix from $1,600 2019-08-27
Debian Linux MEDIUM 6.5
CVE-2019-15531

GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

Fix: after 1.9
Fix from $1,600 2019-08-23
Debian Linux MEDIUM 6.5
CVE-2019-12746

An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS…

Fix: after 6.0.19
Fix from $1,600 2019-08-21
Debian Linux MEDIUM 6.5
CVE-2019-13458

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19…

Fix: after 7.0.8
Fix from $1,600 2019-08-21
Debian Linux HIGH 7.8
CVE-2019-15296

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer ove…

Patch available
Fix from $1,950 2019-08-21
Debian Linux MEDIUM 5.5
CVE-2019-15145

DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image…

Patch available
Fix from $1,600 2019-08-18
Debian Linux MEDIUM 5.5
CVE-2019-15142

In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup …

Patch available
Fix from $1,600 2019-08-18
Debian Linux MEDIUM 5.5
CVE-2019-15143

In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_r…

No fix yet
Fix from $1,600 2019-08-18
Debian Linux MEDIUM 5.5
CVE-2019-15144

In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due …

Patch available
Fix from $1,600 2019-08-18
Debian Linux MEDIUM 5.3
CVE-2019-15132

Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability o…

Fix: after 5.2.1
Fix from $1,600 2019-08-17
Debian Linux HIGH 7.8
CVE-2019-13221

A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux HIGH 7.1
CVE-2019-13220

Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service o…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux HIGH 7.1
CVE-2019-13222

An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service o…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux MEDIUM 5.5
CVE-2019-13219

A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a c…

Fix: after 2019-03-04
Fix from $1,600 2019-08-15
Debian Linux MEDIUM 5.5
CVE-2019-13223

A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a cr…

Fix: after 2019-03-04
Fix from $1,600 2019-08-15