Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.8
CVE-2019-7577

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 7.8
CVE-2018-20760

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 …

Fix: after 0.7.1
Fix from $1,950 2019-02-06
Debian Linux HIGH 7.8
CVE-2018-20761

GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.

Fix: after 0.7.1
Fix from $1,950 2019-02-06
Debian Linux HIGH 7.8
CVE-2018-20762

GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box…

Fix: after 0.7.1
Fix from $1,950 2019-02-06
Debian Linux HIGH 7.8
CVE-2018-20763

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing sz…

Fix: after 0.7.1
Fix from $1,950 2019-02-06
Debian Linux HIGH 7.8
CVE-2019-7548

SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

Patch available
Fix from $1,950 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2019-3463

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to …

Mitigation only
Fix from $2,300 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2019-3464

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restri…

Mitigation only
Fix from $2,300 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2018-8793EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8794EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() an…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8795EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_update…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8797EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8800EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8791

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8792

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (seg…

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8796

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (…

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8798

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8799

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service …

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-4056

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a…

Fix: 4.5.0.9+
Fix from $2,300 2019-02-05
Debian Linux HIGH 7.5
CVE-2019-7395

In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.

Fix: 6.9.10-25 / 7.0.8-25+
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2019-7396

In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.

Fix: 6.9.10-25 / 7.0.8-25+
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2019-7397

In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.

Fix: 6.9.10-25 / 7.0.8-25+
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2019-7398

In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.

Fix: 6.9.10-25 / 7.0.8-25+
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.8
CVE-2019-1000018

rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp p…

No fix yet
Fix from $1,950 2019-02-04
Debian Linux MEDIUM 6.5
CVE-2019-1000019

libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerabil…

Fix: 3.4.0+
Fix from $1,600 2019-02-04
Tmpreaper HIGH 7.0
CVE-2019-3461

Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mo…

Mitigation only
Fix from $1,950 2019-02-04
Debian Linux MEDIUM 5.3
CVE-2019-7317EPSS 9%

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Fix: 8.0.23+
Fix from $1,600 2019-02-04
Debian Linux CRITICAL 9.8
CVE-2019-7314

liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to …

Fix: 0.95+
Fix from $2,300 2019-02-04
Debian Linux HIGH 7.4
CVE-2019-7283

An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. Howev…

Fix: after 0.17
Fix from $1,950 2019-01-31
Debian Linux MEDIUM 5.9
CVE-2019-7282

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty fi…

Fix: after 0.17
Fix from $1,600 2019-01-31