Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2018-10906

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use…

Fix: 2.9.8 / 3.2.5+
Fix from $1,950 2018-07-24
Debian Linux CRITICAL 9.8
CVE-2018-1999010

FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can resu…

Fix: 3.4.3+
Fix from $2,300 2018-07-23
Debian Linux HIGH 8.8
CVE-2018-14447

trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.

Patch available
Fix from $1,950 2018-07-20
Debian Linux HIGH 7.5
CVE-2018-14423

Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow r…

Fix: after 2.3.0
Fix from $1,950 2018-07-19
Debian Linux MEDIUM 6.5
CVE-2018-14395

libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with …

Patch available
Fix from $1,600 2018-07-19
Debian Linux HIGH 7.2
CVE-2018-10871

389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retr…

Fix: 1.3.8.5 / 1.4.0.12+
Fix from $1,950 2018-07-18
Debian Linux HIGH 7.5
CVE-2018-14363

An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache …

Fix: 20180716+
Fix from $1,950 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14349

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14350EPSS 5%

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi…

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14356

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14360

An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.

Fix: 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14361

An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.

Fix: 20180716+
Fix from $2,300 2018-07-17
Debian Linux MEDIUM 5.3
CVE-2018-14355

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.

Fix: 1.10.1 / 20180716+
Fix from $1,600 2018-07-17
Debian Linux HIGH 8.8
CVE-2018-14346

GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

Fix: 1.7+
Fix from $1,950 2018-07-17
Debian Linux MEDIUM 6.5
CVE-2018-14347

GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).

Fix: 1.7+
Fix from $1,600 2018-07-17
Debian Linux HIGH 7.5
CVE-2018-14337

The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory ac…

No fix yet
Fix from $1,950 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-12584EPSS 25%

The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a deni…

Fix: after 1.10.2
Fix from $2,300 2018-07-16
Debian Linux HIGH 7.5
CVE-2018-10857

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex reposi…

Mitigation only
Fix from $1,950 2018-07-16
Debian Linux HIGH 7.5
CVE-2018-10859

git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypti…

Mitigation only
Fix from $1,950 2018-07-16
Debian Linux MEDIUM 5.5
CVE-2014-2079

X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to …

Patch available
Fix from $1,600 2018-07-16
Debian Linux MEDIUM 6.5
CVE-2018-14055

ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inje…

Fix: after 1.7.0
Fix from $1,600 2018-07-15
Debian Linux MEDIUM 5.3
CVE-2018-14056

ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.

Fix: after 1.7.0
Fix from $1,600 2018-07-15
Debian Linux MEDIUM 6.1
CVE-2018-14040

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Fix: 3.4.0 / 4.1.2+
Fix from $1,600 2018-07-13
Debian Linux HIGH 8.0
CVE-2018-11529EPSS 41%

VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV f…

Fix: after 2.2.8
Fix from $1,950 2018-07-11
Debian Linux HIGH 8.1
CVE-2018-10887

A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c fi…

Fix: 0.27.3+
Fix from $1,950 2018-07-10
Debian Linux MEDIUM 6.5
CVE-2018-10888

A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read whil…

Fix: 0.27.3+
Fix from $1,600 2018-07-10
Debian Linux HIGH 8.8
CVE-2018-13302

In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_ea…

Patch available
Fix from $1,950 2018-07-05
Debian Linux HIGH 8.1
CVE-2018-13300

In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavfo…

Patch available
Fix from $1,950 2018-07-05
Debian Linux HIGH 8.8
CVE-2018-13139

A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash)…

Mitigation only
Fix from $1,950 2018-07-04
Debian Linux CRITICAL 9.9
CVE-2018-12892

An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…

Fix: after 4.10.1
Fix from $2,300 2018-07-02