Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.6
CVE-2018-17961EPSS 10%

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this i…

Patch available
Fix from $1,950 2018-10-15
Debian Linux MEDIUM 5.5
CVE-2018-18310

An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows …

Fix: after 0.174
Fix from $1,600 2018-10-15
Debian Linux MEDIUM 5.9
CVE-2018-16758

Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryptio…

Fix: after 1.0.34
Fix from $1,600 2018-10-10
Debian Linux CRITICAL 9.8
CVE-2018-17963

qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possib…

Fix: after 3.0.0
Fix from $2,300 2018-10-09
Debian Linux MEDIUM 6.5
CVE-2018-18088

OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c

No fix yet
Fix from $1,600 2018-10-09
Debian Linux MEDIUM 6.5
CVE-2018-18065EPSS 17%

_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to …

Fix: 5.8+
Fix from $1,600 2018-10-08
Debian Linux MEDIUM 6.5
CVE-2018-18025

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a d…

Patch available
Fix from $1,600 2018-10-07
Debian Linux MEDIUM 6.5
CVE-2018-0504

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid

Fix: 1.31.1+
Fix from $1,600 2018-10-04
Debian Linux MEDIUM 6.5
CVE-2018-0505

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock

Fix: 1.31.1+
Fix from $1,600 2018-10-04
Debian Linux HIGH 7.5
CVE-2018-17540

The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.

Fix: 5.7.1+
Fix from $1,950 2018-10-03
Debian Linux HIGH 7.8
CVE-2015-9268

Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechani…

Fix: 2.49+
Fix from $1,950 2018-10-01
Debian Linux MEDIUM 5.5
CVE-2015-9267

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This al…

Fix: 2.49+
Fix from $1,600 2018-10-01
Debian Linux HIGH 7.5
CVE-2018-14648EPSS 6%

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An un…

Fix: 1.4.0.17+
Fix from $1,950 2018-09-28
Debian Linux MEDIUM 6.5
CVE-2018-17581

CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of se…

Patch available
Fix from $1,600 2018-09-28
Debian Linux MEDIUM 6.5
CVE-2018-16587

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to a…

Fix: 4.0.32 / 5.0.30+
Fix from $1,600 2018-09-28
Debian Linux HIGH 7.5
CVE-2018-16151

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GM…

Fix: 5.7.0+
Fix from $1,950 2018-09-26
Debian Linux HIGH 7.5
CVE-2018-16152

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GM…

Fix: 5.7.0+
Fix from $1,950 2018-09-26
Debian Linux HIGH 7.5
CVE-2018-17281EPSS 53%

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 1…

Fix: after 15.6.0
Fix from $1,950 2018-09-24
Debian Linux CRITICAL 9.8
CVE-2018-17141EPSS 6%

HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit en…

No fix yet
Fix from $2,300 2018-09-21
Debian Linux HIGH 8.8
CVE-2018-16515

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction…

Fix: 0.33.3.1+
Fix from $1,950 2018-09-18
Debian Linux HIGH 7.5
CVE-2018-13982

Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitiza…

Fix: 3.1.33+
Fix from $1,950 2018-09-18
Debian Linux HIGH 8.8
CVE-2018-17100

An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) o…

Patch available
Fix from $1,950 2018-09-16
Debian Linux HIGH 8.8
CVE-2018-17101

An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a deni…

Patch available
Fix from $1,950 2018-09-16
Debian Linux HIGH 7.5
CVE-2018-12086EPSS 12%

Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.

Fix: after 1.03.352.12
Fix from $1,950 2018-09-14
Debian Linux MEDIUM 6.5
CVE-2018-17000

A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an a…

No fix yet
Fix from $1,600 2018-09-13
Debian Linux HIGH 7.8
CVE-2018-16741

An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to p…

Fix: 1.2.1+
Fix from $1,950 2018-09-13
Debian Linux HIGH 8.8
CVE-2018-16981

stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.

No fix yet
Fix from $1,950 2018-09-12
Debian Linux CRITICAL 9.8
CVE-2018-16947

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not…

Fix: 1.6.23 / 1.8.2+
Fix from $2,300 2018-09-12
Debian Linux HIGH 7.5
CVE-2018-16948

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables …

Fix: 1.6.23 / 1.8.2+
Fix from $1,950 2018-09-12
Debian Linux HIGH 7.5
CVE-2018-16949

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded…

Fix: 1.6.23 / 1.8.2+
Fix from $1,950 2018-09-12