Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2019-7165

A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2019-07-03
Debian Linux HIGH 7.8
CVE-2019-13164

qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limit…

Patch available
Fix from $1,950 2019-07-03
Debian Linux CRITICAL 9.8
CVE-2019-12594EPSS 7%

DOSBox 0.74-2 has Incorrect Access Control.

No fix yet
Fix from $2,300 2019-07-02
Debian Linux MEDIUM 6.5
CVE-2019-13147

In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows…

No fix yet
Fix from $1,600 2019-07-02
Debian Linux HIGH 8.8
CVE-2019-13135

ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.

Fix: 6.9.10-50 / 7.0.8-50+
Fix from $1,950 2019-07-01
Debian Linux MEDIUM 6.5
CVE-2019-13137

ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.

Fix: 6.9.10-50 / 7.0.8-50+
Fix from $1,600 2019-07-01
Debian Linux MEDIUM 5.3
CVE-2019-13117EPSS 6%

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This c…

Patch available
Fix from $1,600 2019-07-01
Debian Linux HIGH 8.1
CVE-2019-13031

LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notific…

Fix: 1.9.20+
Fix from $1,950 2019-06-28
Debian Linux HIGH 8.8
CVE-2018-20847

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can le…

Fix: after 2.3.0
Fix from $1,950 2019-06-26
Debian Linux HIGH 7.8
CVE-2019-12979

ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to Acq…

Patch available
Fix from $1,950 2019-06-26
Debian Linux MEDIUM 5.5
CVE-2019-12973

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerabili…

Patch available
Fix from $1,600 2019-06-26
Debian Linux MEDIUM 5.5
CVE-2019-12975

ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.

Patch available
Fix from $1,600 2019-06-26
Debian Linux MEDIUM 5.5
CVE-2019-12976

ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.

Patch available
Fix from $1,600 2019-06-26
Debian Linux MEDIUM 5.9
CVE-2019-12384EPSS 45%

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core clas…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,600 2019-06-24
Debian Linux CRITICAL 9.8
CVE-2019-12900EPSS 8%

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

Fix: 3.7.13 / 3.8.13+
Fix from $2,300 2019-06-19
Debian Linux MEDIUM 5.9
CVE-2019-12814EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a s…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,600 2019-06-19
Debian Linux HIGH 7.5
CVE-2019-8321

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injec…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 7.5
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. T…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 7.5
CVE-2019-8323

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 8.8
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacke…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 7.5
CVE-2019-8325

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence in…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux MEDIUM 5.3
CVE-2019-12497

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x…

Fix: after 7.0.8
Fix from $1,600 2019-06-17
Debian Linux MEDIUM 5.5
CVE-2019-2101

In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local infor…

No fix yet
Fix from $1,600 2019-06-07
Debian Linux HIGH 7.8
CVE-2019-12483

An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx…

Fix: after 0.7.1
Fix from $1,950 2019-05-30
Debian Linux HIGH 7.5
CVE-2019-12482

An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c …

Fix: after 0.7.1
Fix from $1,950 2019-05-30
Debian Linux MEDIUM 5.5
CVE-2019-12481

An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated b…

Fix: after 0.7.1
Fix from $1,600 2019-05-30
Debian Linux CRITICAL 9.8
CVE-2019-12450

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progre…

Fix: after 2.61.1
Fix from $2,300 2019-05-29
Debian Linux HIGH 8.8
CVE-2019-9858EPSS 19%

Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image…

No fix yet
Fix from $1,950 2019-05-29
Debian Linux CRITICAL 9.8
CVE-2019-12046

LemonLDAP::NG -2.0.3 has Incorrect Access Control.

No fix yet
Fix from $2,300 2019-05-22
Debian Linux MEDIUM 6.5
CVE-2019-9892

An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged…

Fix: after 7.0.6
Fix from $1,600 2019-05-22