Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2018-20748

LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.

Fix: 0.9.12 / 3.2.1.0+
Fix from $2,300 2019-01-30
Debian Linux MEDIUM 6.5
CVE-2019-7149

A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cau…

Patch available
Fix from $1,600 2019-01-29
Debian Linux MEDIUM 5.5
CVE-2019-7150

An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segm…

Patch available
Fix from $1,600 2019-01-29
Advanced Package Tool HIGH 8.1
CVE-2019-3462EPSS 15%

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM att…

Fix: 1.2.30+
Fix from $1,950 2019-01-28
Debian Linux CRITICAL 9.8
CVE-2019-6978

The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is un…

Patch available
Fix from $2,300 2019-01-28
Debian Linux MEDIUM 5.9
CVE-2019-6799EPSS 15%

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL…

Fix: after 4.8.4
Fix from $1,600 2019-01-26
Debian Linux HIGH 7.5
CVE-2018-20743

murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote att…

Fix: after 1.2.19
Fix from $1,950 2019-01-25
Debian Linux HIGH 7.1
CVE-2019-6956

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.

Fix: 2.9.0+
Fix from $1,950 2019-01-25
Debian Linux MEDIUM 5.3
CVE-2017-3138EPSS 6%

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel…

Mitigation only
Fix from $1,600 2019-01-16
Debian Linux CRITICAL 9.8
CVE-2018-20721

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address c…

Fix: 0.9.1+
Fix from $2,300 2019-01-16
Debian Linux MEDIUM 5.2
CVE-2019-3811

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the…

Fix: 2.1+
Fix from $1,600 2019-01-15
Debian Linux CRITICAL 9.8
CVE-2019-6256

A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer cr…

No fix yet
Fix from $2,300 2019-01-14
Debian Linux HIGH 8.8
CVE-2019-6250EPSS 9%

A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::…

Fix: 4.3.1+
Fix from $1,950 2019-01-13
Debian Linux HIGH 8.8
CVE-2019-6245

An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned …

Patch available
Fix from $1,950 2019-01-13
Debian Linux HIGH 7.8
CVE-2018-4180

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

Fix: 10.13.5+
Fix from $1,950 2019-01-11
Debian Linux MEDIUM 6.7
CVE-2019-6133

In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization deci…

Patch available
Fix from $1,600 2019-01-11
Debian Linux MEDIUM 5.3
CVE-2018-20685

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. …

Fix: after 7.9
Fix from $1,600 2019-01-10
Debian Linux MEDIUM 6.5
CVE-2018-20662

In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of…

Patch available
Fix from $1,600 2019-01-03
Debian Linux MEDIUM 5.5
CVE-2018-19478

In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

Fix: 9.26+
Fix from $1,600 2019-01-02
Debian Linux CRITICAL 10.0
CVE-2018-14721EPSS 10%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14718EPSS 13%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14719EPSS 10%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt an…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14720EPSS 8%

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19360EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms c…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19361EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from po…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19362EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core cla…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux HIGH 7.8
CVE-2019-3500

aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to …

Patch available
Fix from $1,950 2019-01-02
Debian Linux MEDIUM 6.5
CVE-2018-20622

JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.

Mitigation only
Fix from $1,600 2018-12-31
Debian Linux MEDIUM 6.5
CVE-2018-20584

JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.

Patch available
Fix from $1,600 2018-12-30
Debian Linux MEDIUM 6.5
CVE-2018-20570

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

No fix yet
Fix from $1,600 2018-12-28