Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2019-11187

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t…

Fix: after 2019-04-11
Fix from $2,300 2019-08-15
Debian Linux HIGH 7.8
CVE-2019-13217

A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbi…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux HIGH 7.5
CVE-2019-12854EPSS 12%

Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, thi…

Fix: after 4.7
Fix from $1,950 2019-08-15
Debian Linux MEDIUM 5.5
CVE-2019-13218

Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted …

Fix: after 2019-03-04
Fix from $1,600 2019-08-15
Debian Linux MEDIUM 6.5
CVE-2019-14973

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavio…

Fix: after 4.0.10
Fix from $1,600 2019-08-14
Debian Linux MEDIUM 6.5
CVE-2019-14981

In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an att…

Fix: 6.9.10-41 / 7.0.8-41+
Fix from $1,600 2019-08-12
Debian Linux HIGH 7.8
CVE-2019-14744

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This r…

Fix: 5.61.0+
Fix from $1,950 2019-08-07
Debian Linux HIGH 7.5
CVE-2019-14513

Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation be…

Fix: 2.76+
Fix from $1,950 2019-08-01
Debian Linux HIGH 7.5
CVE-2019-14493

An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persiste…

Fix: 4.1.1+
Fix from $1,950 2019-08-01
Debian Linux HIGH 8.6
CVE-2019-10185

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attack…

Fix: after 1.7.2
Fix from $1,950 2019-07-31
Debian Linux HIGH 8.1
CVE-2019-10181

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signatu…

Fix: after 1.7.2
Fix from $1,950 2019-07-31
Debian Linux HIGH 7.5
CVE-2019-14459

nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order t…

Fix: after 1.6.17
Fix from $1,950 2019-07-31
Debian Linux MEDIUM 6.5
CVE-2019-14380

libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.

Fix: 0.4.5+
Fix from $1,600 2019-07-30
Debian Linux MEDIUM 6.5
CVE-2019-14442

In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. …

No fix yet
Fix from $1,600 2019-07-30
Debian Linux MEDIUM 6.5
CVE-2019-14443

An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of …

No fix yet
Fix from $1,600 2019-07-30
Debian Linux HIGH 7.5
CVE-2019-14439EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either global…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,950 2019-07-30
Debian Linux CRITICAL 9.8
CVE-2019-14379EPSS 8%

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transact…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $2,300 2019-07-29
Debian Linux MEDIUM 6.5
CVE-2019-14370

In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.

No fix yet
Fix from $1,600 2019-07-28
Debian Linux MEDIUM 6.5
CVE-2019-14369

Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a …

No fix yet
Fix from $1,600 2019-07-28
Debian Linux HIGH 7.8
CVE-2019-13638

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…

Patch available
Fix from $1,950 2019-07-26
Debian Linux MEDIUM 5.5
CVE-2019-14275

Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.

No fix yet
Fix from $1,600 2019-07-26
Debian Linux CRITICAL 9.8
CVE-2019-13917EPSS 9%

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for item…

Fix: after 4.92
Fix from $2,300 2019-07-25
Debian Linux CRITICAL 9.8
CVE-2019-1010174

CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attac…

Fix: 2.3.4+
Fix from $2,300 2019-07-25
Debian Linux MEDIUM 5.3
CVE-2019-2769

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java S…

Patch available
Fix from $1,600 2019-07-23
Debian Linux MEDIUM 5.1
CVE-2019-2745

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and…

Fix: 8.7.0-00+
Fix from $1,600 2019-07-23
Debian Linux MEDIUM 6.5
CVE-2019-9959

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereb…

Fix: after 0.78.0
Fix from $1,600 2019-07-22
Debian Linux CRITICAL 9.8
CVE-2019-13962

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not pr…

Fix: after 3.0.7
Fix from $2,300 2019-07-18
Debian Linux MEDIUM 5.5
CVE-2019-1010069

moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of service attack via a crafted f…

No fix yet
Fix from $1,600 2019-07-18
Debian Linux HIGH 8.1
CVE-2019-13115EPSS 12%

In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-b…

Fix: 1.9.0+
Fix from $1,950 2019-07-16
Debian Linux HIGH 8.1
CVE-2019-13616

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called f…

No fix yet
Fix from $1,950 2019-07-16