Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.9
CVE-2016-7073

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middl…

Fix: 3.4.11 / 3.7.4+
Fix from $1,600 2018-09-11
Debian Linux MEDIUM 5.9
CVE-2016-7074

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middl…

Fix: 3.4.11 / 4.0.2+
Fix from $1,600 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7068EPSS 7%

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacke…

Fix: 3.4.11 / 3.7.4+
Fix from $1,950 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7072EPSS 6%

An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of ser…

Fix: 3.4.11 / 4.0.2+
Fix from $1,950 2018-09-10
Debian Linux HIGH 7.8
CVE-2018-16802

An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception …

Mitigation only
Fix from $1,950 2018-09-10
Debian Linux CRITICAL 9.8
CVE-2018-16657

In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. T…

Fix: 5.0.7 / 5.1.4+
Fix from $2,300 2018-09-07
Debian Linux MEDIUM 6.5
CVE-2018-16646

In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this fo…

Patch available
Fix from $1,600 2018-09-06
Debian Linux MEDIUM 6.1
CVE-2018-1000671

sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of th…

No fix yet
Fix from $1,600 2018-09-06
Debian Linux MEDIUM 5.5
CVE-2018-1000801

okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that ca…

Fix: after 18.08
Fix from $1,600 2018-09-06
Debian Linux HIGH 7.8
CVE-2018-16509EPSS 92%

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exception…

Fix: 9.24 / 9.26+
Fix from $1,950 2018-09-05
Debian Linux HIGH 7.8
CVE-2018-16511

An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted Post…

Patch available
Fix from $1,950 2018-09-05
Debian Linux HIGH 8.8
CVE-2018-10929

A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files an…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.8
CVE-2018-10928

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gl…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.1
CVE-2018-10927

A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and exec…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.8
CVE-2018-16430

GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.

Fix: after 1.7
Fix from $1,950 2018-09-04
Debian Linux CRITICAL 9.8
CVE-2018-16402

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecif…

No fix yet
Fix from $2,300 2018-09-03
Debian Linux HIGH 8.8
CVE-2018-16335

newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-bas…

Patch available
Fix from $1,950 2018-09-02
Debian Linux MEDIUM 5.5
CVE-2018-16062

dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer…

Fix: 0.174+
Fix from $1,600 2018-08-29
Debian Linux MEDIUM 6.5
CVE-2017-15415

Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML pag…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Debian Linux HIGH 7.8
CVE-2018-15911

In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode ope…

Patch available
Fix from $1,950 2018-08-28
Debian Linux HIGH 7.8
CVE-2018-15908

In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write fil…

Fix: after 9.23
Fix from $1,950 2018-08-27
Debian Linux HIGH 7.8
CVE-2018-15909

In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScri…

Patch available
Fix from $1,950 2018-08-27
Debian Linux HIGH 7.8
CVE-2018-15910

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter…

Fix: 9.24 / 9.26+
Fix from $1,950 2018-08-27
Debian Linux HIGH 7.5
CVE-2018-15822

The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.

Fix: after 2.8
Fix from $1,950 2018-08-23
Debian Linux HIGH 8.8
CVE-2018-10858

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use th…

Fix: 4.6.16 / 4.7.9+
Fix from $1,950 2018-08-22
Debian Linux HIGH 7.8
CVE-2018-10902

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_…

Patch available
Fix from $1,950 2018-08-21
Debian Linux MEDIUM 5.3
CVE-2018-15599

The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validi…

Fix: after 2018.76
Fix from $1,600 2018-08-21
Debian Linux HIGH 7.8
CVE-2018-1000637

zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary…

Fix: after 1.8
Fix from $1,950 2018-08-20
Debian Linux HIGH 7.5
CVE-2018-1000632EPSS 7%

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can res…

Fix: 2.0.3 / 2.1.1+
Fix from $1,950 2018-08-20
Debian Linux MEDIUM 5.5
CVE-2018-15594

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectr…

Fix: 4.18.1+
Fix from $1,600 2018-08-20