Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2019-13602

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause…

Fix: after 3.0.7.1
Fix from $1,950 2019-07-14
Debian Linux MEDIUM 5.3
CVE-2019-13161

An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk throug…

Fix: 13.27.1 / 15.7.3+
Fix from $1,600 2019-07-12
Debian Linux HIGH 7.8
CVE-2019-13574EPSS 8%

In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input…

Fix: 4.9.4+
Fix from $1,950 2019-07-12
Debian Linux HIGH 7.8
CVE-2019-0053

Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exp…

No fix yet
Fix from $1,950 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-12525EPSS 24%

An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the heade…

Fix: after 4.7
Fix from $2,300 2019-07-11
Debian Linux MEDIUM 5.9
CVE-2019-12529EPSS 8%

An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authenticati…

Fix: 2.7+
Fix from $1,600 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-12838

SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.

Fix: after 18.08.7
Fix from $2,300 2019-07-11
Debian Linux MEDIUM 6.5
CVE-2019-13504

There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

Fix: after 0.27.2
Fix from $1,600 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-13132EPSS 42%

In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, runni…

Fix: 4.0.9 / 4.1.7+
Fix from $2,300 2019-07-10
Debian Linux MEDIUM 6.5
CVE-2019-12469

MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 an…

Fix: 1.27.6 / 1.30.2+
Fix from $1,600 2019-07-10
Debian Linux MEDIUM 6.5
CVE-2019-12470

Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 an…

Fix: 1.27.6 / 1.30.2+
Fix from $1,600 2019-07-10
Debian Linux HIGH 8.8
CVE-2019-12466

Wikimedia MediaWiki through 1.32.1 allows CSRF.

Fix: after 1.32.1
Fix from $1,950 2019-07-10
Debian Linux HIGH 7.5
CVE-2019-12473

Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table…

Fix: 1.27.6 / 1.30.2+
Fix from $1,950 2019-07-10
Debian Linux HIGH 7.5
CVE-2019-12474

Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled m…

Fix: 1.27.6 / 1.30.2+
Fix from $1,950 2019-07-10
Debian Linux MEDIUM 6.1
CVE-2019-12471

Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perfo…

Fix: 1.30.2 / 1.31.2+
Fix from $1,600 2019-07-10
Debian Linux CRITICAL 9.8
CVE-2019-12468

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow…

Fix: after 1.32.1
Fix from $2,300 2019-07-10
Debian Linux MEDIUM 5.3
CVE-2019-12467

MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or…

Fix: 1.27.6 / 1.30.2+
Fix from $1,600 2019-07-10
Debian Linux MEDIUM 6.5
CVE-2019-13454

ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.

Fix: after 7.0.8-54
Fix from $1,600 2019-07-09
Debian Linux MEDIUM 6.1
CVE-2019-13345EPSS 74%

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

Fix: after 4.7
Fix from $1,600 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-13297

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-13300

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13304

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13305

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13306

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13307

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.

Patch available
Fix from $1,950 2019-07-05
Debian Linux MEDIUM 6.5
CVE-2019-13301

ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.

Patch available
Fix from $1,600 2019-07-05
Debian Linux MEDIUM 6.5
CVE-2019-13309

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/…

Patch available
Fix from $1,600 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-13295

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-5051

An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead…

No fix yet
Fix from $1,950 2019-07-03
Debian Linux HIGH 8.8
CVE-2019-5052

An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overf…

No fix yet
Fix from $1,950 2019-07-03