Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2019-7175

In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.

Fix: 6.9.10-25 / 7.0.8-25+
Fix from $1,950 2019-03-07
Debian Linux HIGH 7.8
CVE-2019-1999

In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privileg…

No fix yet
Fix from $1,950 2019-02-28
Debian Linux CRITICAL 9.8
CVE-2019-9215

In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.

Fix: 2019.02.27+
Fix from $2,300 2019-02-28
Debian Linux HIGH 7.8
CVE-2019-9210

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted m…

No fix yet
Fix from $1,950 2019-02-27
Debian Linux HIGH 8.8
CVE-2019-9200

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending…

No fix yet
Fix from $1,950 2019-02-26
Debian Linux HIGH 7.5
CVE-2018-5817

A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited …

Fix: 0.19.1+
Fix from $1,950 2019-02-20
Debian Linux HIGH 7.5
CVE-2018-5818

An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infin…

Fix: 0.19.1+
Fix from $1,950 2019-02-20
Debian Linux HIGH 7.5
CVE-2018-5819

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust availa…

Fix: 0.19.1+
Fix from $1,950 2019-02-20
Debian Linux CRITICAL 9.8
CVE-2019-7164

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Fix: after 1.2.17
Fix from $2,300 2019-02-20
Debian Linux HIGH 8.8
CVE-2019-8907

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or…

No fix yet
Fix from $1,950 2019-02-18
Debian Linux MEDIUM 6.1
CVE-2016-10742

Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the req…

Fix: after 3.4.3
Fix from $1,600 2019-02-17
Debian Linux HIGH 7.8
CVE-2019-8379

An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can …

Fix: 2.1+
Fix from $1,950 2019-02-17
Debian Linux HIGH 7.8
CVE-2019-8383

An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be trigg…

Fix: after 2.1
Fix from $1,950 2019-02-17
Debian Linux MEDIUM 5.0
CVE-2019-8354

An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When t…

Mitigation only
Fix from $1,600 2019-02-15
Debian Linux HIGH 8.2
CVE-2019-8308

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side…

Fix: 1.0.7+
Fix from $1,950 2019-02-12
Debian Linux MEDIUM 6.5
CVE-2018-15587

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a va…

Fix: after 3.28.2
Fix from $1,600 2019-02-11
Debian Linux MEDIUM 6.5
CVE-2019-7663

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpS…

Patch available
Fix from $1,600 2019-02-09
Debian Linux MEDIUM 5.5
CVE-2019-7665

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can…

No fix yet
Fix from $1,600 2019-02-09
Debian Linux HIGH 8.1
CVE-2019-7659

Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impa…

Fix: 2.8.75+
Fix from $1,950 2019-02-09
Debian Linux CRITICAL 9.8
CVE-2019-7653

The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowi…

No fix yet
Fix from $2,300 2019-02-09
Debian Linux HIGH 8.8
CVE-2019-7637

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.8
CVE-2019-7638

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.1
CVE-2019-7635

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.1
CVE-2019-7636

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.1
CVE-2019-7578

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7572

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7573

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the…

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7574

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7575

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7576

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside th…

Fix: after 2.0.9
Fix from $1,950 2019-02-07