Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2019-12086EPSS 22%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a sp…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,950 2019-05-17
Debian Linux HIGH 7.8
CVE-2019-3839

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted P…

Fix: 9.27+
Fix from $1,950 2019-05-16
Debian Linux HIGH 7.5
CVE-2019-12111

A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.

Fix: after 2.1
Fix from $1,950 2019-05-15
Debian Linux CRITICAL 9.8
CVE-2019-11766

dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.

Fix: 6.11.7 / 7.2.2+
Fix from $2,300 2019-05-05
Debian Linux CRITICAL 9.8
CVE-2019-11627

gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.

Fix: 2.10+
Fix from $2,300 2019-04-30
Debian Linux HIGH 7.8
CVE-2019-5429

Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directo…

Fix: 3.41.0+
Fix from $1,950 2019-04-29
Debian Linux MEDIUM 5.3
CVE-2019-11579

dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.

Fix: 7.2.1+
Fix from $1,600 2019-04-28
Debian Linux HIGH 8.8
CVE-2019-11506

In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/m…

Patch available
Fix from $1,950 2019-04-24
Debian Linux HIGH 8.8
CVE-2019-11505

In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c…

Fix: after 1.3.31
Fix from $1,950 2019-04-24
Debian Linux HIGH 8.8
CVE-2019-9928EPSS 6%

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing rem…

Fix: 1.16.0+
Fix from $1,950 2019-04-24
Debian Linux MEDIUM 6.1
CVE-2019-10241EPSS 10%

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES…

Fix: after 11.7.0
Fix from $1,600 2019-04-22
Debian Linux MEDIUM 5.3
CVE-2019-10247EPSS 6%

In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combinati…

Fix: after 3.1.3
Fix from $1,600 2019-04-22
Debian Linux HIGH 8.1
CVE-2019-11455

A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of a…

Fix: 5.25.3+
Fix from $1,950 2019-04-22
Debian Linux MEDIUM 5.9
CVE-2019-3902

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil…

Fix: 4.9+
Fix from $1,600 2019-04-22
Debian Linux HIGH 8.8
CVE-2019-11338

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,950 2019-04-19
Debian Linux HIGH 7.5
CVE-2019-3883EPSS 8%

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout'…

Fix: after 1.4.1.2
Fix from $1,950 2019-04-17
Debian Linux HIGH 7.8
CVE-2019-11221

GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

No fix yet
Fix from $1,950 2019-04-15
Debian Linux HIGH 7.8
CVE-2019-11222

gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.

Patch available
Fix from $1,950 2019-04-15
Debian Linux HIGH 8.8
CVE-2019-11071

SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishand…

Fix: 3.1.10 / 3.2.4+
Fix from $1,950 2019-04-10
Debian Linux MEDIUM 5.4
CVE-2019-3880

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this fla…

Fix: 4.8.11 / 4.9.6+
Fix from $1,600 2019-04-09
Debian Linux MEDIUM 5.4
CVE-2019-11025

In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options)…

Fix: 1.2.3+
Fix from $1,600 2019-04-08
Debian Linux MEDIUM 5.5
CVE-2019-1788

A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior c…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Debian Linux CRITICAL 9.1
CVE-2019-11006

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attac…

Fix: after 1.3.31
Fix from $2,300 2019-04-08
Debian Linux HIGH 8.8
CVE-2019-11008

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote …

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Debian Linux HIGH 8.1
CVE-2019-11007

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attacke…

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Debian Linux HIGH 8.1
CVE-2019-11009

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attacke…

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Debian Linux MEDIUM 6.5
CVE-2019-11010

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a de…

Fix: after 1.3.31
Fix from $1,600 2019-04-08
Debian Linux MEDIUM 5.5
CVE-2019-1787

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could all…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Debian Linux MEDIUM 6.1
CVE-2019-10904

Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

No fix yet
Fix from $1,600 2019-04-06
Debian Linux MEDIUM 6.5
CVE-2019-10868

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authe…

Fix: 4.2.21 / 4.4.19+
Fix from $1,600 2019-04-05