Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2018-15572

The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context swi…

Fix: 4.18.1+
Fix from $1,600 2018-08-20
Debian Linux CRITICAL 9.8
CVE-2018-15494

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

Fix: 1.14+
Fix from $2,300 2018-08-18
Debian Linux HIGH 7.5
CVE-2018-15501

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packe…

Fix: 0.26.6 / 0.27.4+
Fix from $1,950 2018-08-18
Debian Linux MEDIUM 5.3
CVE-2018-15473EPSS 99%

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packe…

Fix: after 7.7
Fix from $1,600 2018-08-17
Debian Linux MEDIUM 6.5
CVE-2018-15469

An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an…

Fix: after 4.11.0
Fix from $1,600 2018-08-17
Debian Linux HIGH 8.8
CVE-2018-10873

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check…

Patch available
Fix from $1,950 2018-08-17
Debian Linux HIGH 8.1
CVE-2018-14348

libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

Fix: after 0.41
Fix from $1,950 2018-08-14
Debian Linux HIGH 8.8
CVE-2018-15209

ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and …

No fix yet
Fix from $1,950 2018-08-08
Debian Linux HIGH 8.8
CVE-2018-14593

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is …

Fix: after 6.0.9
Fix from $1,950 2018-08-04
Debian Linux HIGH 7.5
CVE-2018-14912EPSS 93%

cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cg…

Fix: 1.2.1+
Fix from $1,950 2018-08-03
Debian Linux CRITICAL 9.8
CVE-2015-9262EPSS 6%

_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a…

Fix: 1.1.15+
Fix from $2,300 2018-08-01
Debian Linux HIGH 7.8
CVE-2016-8654

A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before…

Fix: 2.0.0+
Fix from $1,950 2018-08-01
Debian Linux MEDIUM 6.5
CVE-2016-9572

A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for de…

Patch available
Fix from $1,600 2018-08-01
Debian Linux MEDIUM 5.3
CVE-2018-14432

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may by…

Fix: 11.0.4+
Fix from $1,600 2018-07-31
Debian Linux HIGH 7.4
CVE-2018-8019

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for r…

Fix: after 1.2.16
Fix from $1,950 2018-07-31
Debian Linux HIGH 7.4
CVE-2018-8020

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multi…

Fix: after 1.2.16
Fix from $1,950 2018-07-31
Debian Linux CRITICAL 9.8
CVE-2018-14767EPSS 29%

In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…

Fix: 5.0.7 / 5.1.4+
Fix from $2,300 2018-07-31
Debian Linux MEDIUM 5.5
CVE-2018-10883

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of s…

Fix: 4.9.110+
Fix from $1,600 2018-07-30
Debian Linux MEDIUM 5.9
CVE-2018-0497

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuit…

Fix: 2.1.14 / 2.7.5+
Fix from $1,600 2018-07-28
Debian Linux HIGH 7.5
CVE-2016-9578

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send …

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Debian Linux HIGH 8.8
CVE-2016-9577

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th…

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Debian Linux CRITICAL 9.8
CVE-2017-2640EPSS 6%

An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla…

Fix: 2.12.0+
Fix from $2,300 2018-07-27
Debian Linux HIGH 7.0
CVE-2017-2624

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the co…

Fix: after 1.19.4
Fix from $1,950 2018-07-27
Debian Linux HIGH 7.5
CVE-2017-15120EPSS 52%

An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing…

Fix: 4.0.8+
Fix from $1,950 2018-07-27
Debian Linux HIGH 7.4
CVE-2017-12151

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The con…

Fix: 4.4.16 / 4.5.14+
Fix from $1,950 2018-07-27
Debian Linux MEDIUM 5.5
CVE-2015-9261

huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during a…

Fix: 1.27.2+
Fix from $1,600 2018-07-26
Debian Linux MEDIUM 5.4
CVE-2018-0618

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via uns…

Fix: after 2.1.26
Fix from $1,600 2018-07-26
Debian Linux HIGH 7.8
CVE-2018-10900EPSS 5%

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can b…

Fix: 1.2.6+
Fix from $1,950 2018-07-26
Debian Linux MEDIUM 5.5
CVE-2018-1002200EPSS 13%

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an arc…

Fix: 3.6.0+
Fix from $1,600 2018-07-25
Debian Linux MEDIUM 5.5
CVE-2018-10880

Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_updat…

Fix: 4.17.6+
Fix from $1,600 2018-07-25