Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2018-10242

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the alloca…

Mitigation only
Fix from $1,950 2019-04-04
Debian Linux HIGH 8.1
CVE-2019-10650

In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to caus…

Patch available
Fix from $1,950 2019-03-30
Debian Linux MEDIUM 5.5
CVE-2019-10649

In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of s…

Patch available
Fix from $1,600 2019-03-30
Debian Linux HIGH 7.8
CVE-2019-7524

In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to…

Fix: 2.2.36.3 / 2.3.5.1+
Fix from $1,950 2019-03-28
Debian Linux HIGH 7.5
CVE-2017-7655

In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for …

Fix: after 1.4.15
Fix from $1,950 2019-03-27
Debian Linux CRITICAL 9.1
CVE-2019-3860EPSS 5%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compr…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
Debian Linux CRITICAL 9.1
CVE-2019-3861EPSS 5%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length a…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-3856EPSS 6%

An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are …

Patch available
Fix from $1,950 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-3857EPSS 6%

An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets…

Patch available
Fix from $1,950 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-3863

A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive respons…

Fix: 1.8.1+
Fix from $1,950 2019-03-25
Debian Linux MEDIUM 5.5
CVE-2019-10018

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.

No fix yet
Fix from $1,600 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-9956EPSS 6%

In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a d…

No fix yet
Fix from $1,950 2019-03-24
Debian Linux HIGH 7.8
CVE-2019-9924

rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permis…

Fix: 4.4+
Fix from $1,950 2019-03-22
Debian Linux MEDIUM 5.5
CVE-2019-6454

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer fo…

Patch available
Fix from $1,600 2019-03-21
Debian Linux MEDIUM 5.5
CVE-2019-3832

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header(…

Patch available
Fix from $1,600 2019-03-21
Debian Linux MEDIUM 6.8
CVE-2018-20340

Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could u…

Patch available
Fix from $1,600 2019-03-21
Debian Linux HIGH 7.5
CVE-2018-12022EPSS 7%

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…

Patch available
Fix from $1,950 2019-03-21
Debian Linux HIGH 7.5
CVE-2018-12023EPSS 9%

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…

Patch available
Fix from $1,950 2019-03-21
Debian Linux CRITICAL 9.8
CVE-2018-20177EPSS 8%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() a…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2018-20180EPSS 8%

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_proces…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2018-20181EPSS 8%

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2018-20182EPSS 8%

rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux HIGH 7.5
CVE-2018-20175

rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result…

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Debian Linux HIGH 7.5
CVE-2018-20178

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Servic…

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Debian Linux HIGH 8.8
CVE-2018-17937

gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote att…

Fix: after 3.17
Fix from $1,950 2019-03-13
Debian Linux MEDIUM 6.5
CVE-2019-9718

In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, becau…

Patch available
Fix from $1,600 2019-03-12
Debian Linux MEDIUM 5.5
CVE-2019-9705

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because…

Fix: 3.0pl1-133+
Fix from $1,600 2019-03-12
Cron MEDIUM 5.5
CVE-2019-9706

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_…

Patch available
Fix from $1,600 2019-03-12
Debian Linux HIGH 8.8
CVE-2019-9656

An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.c…

No fix yet
Fix from $1,950 2019-03-11
Debian Linux MEDIUM 5.3
CVE-2019-9658

Checkstyle before 8.18 loads external DTDs by default.

Fix: 8.18+
Fix from $1,600 2019-03-11