Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2018-12891

An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reason Xen explicitly checks for t…

Fix: after 4.10.1
Fix from $1,600 2018-07-02
Debian Linux MEDIUM 6.5
CVE-2018-12893

An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen livelocking with debug except…

Fix: after 4.10.0
Fix from $1,600 2018-07-02
Debian Linux HIGH 8.1
CVE-2018-13054

An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) ot…

Fix: after 3.8.6
Fix from $1,950 2018-07-02
Devscripts CRITICAL 9.8
CVE-2018-13043

scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co…

Fix: after 2.18.3
Fix from $2,300 2018-07-01
Debian Linux CRITICAL 9.8
CVE-2018-13005

An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.

No fix yet
Fix from $2,300 2018-06-29
Debian Linux CRITICAL 9.8
CVE-2018-13006

An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

Patch available
Fix from $2,300 2018-06-29
Debian Linux CRITICAL 9.8
CVE-2017-7658EPSS 21%

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented w…

Fix: 9.3.24 / 9.4.11+
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2018-1000544

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …

Fix: after 1.2.1
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2018-1000550

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that…

Fix: 6.2.32+
Fix from $2,300 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2018-1000517EPSS 33%

BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wge…

Fix: 1.29.0+
Fix from $2,300 2018-06-26
Debian Linux MEDIUM 6.1
CVE-2018-1000528EPSS 46%

GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password fo…

Patch available
Fix from $1,600 2018-06-26
Debian Linux CRITICAL 9.8
CVE-2017-7657EPSS 16%

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transf…

Fix: 9.3.24 / 9.4.11+
Fix from $2,300 2018-06-26
Debian Linux HIGH 7.5
CVE-2017-7656EPSS 6%

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0…

Fix: 9.3.24 / 9.4.11+
Fix from $1,950 2018-06-26
Debian Linux HIGH 7.5
CVE-2018-10852

The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can s…

Fix: 1.16.3+
Fix from $1,950 2018-06-26
Debian Linux HIGH 7.5
CVE-2017-2669

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sen…

Fix: after 2.2.28
Fix from $1,950 2018-06-21
Debian Linux CRITICAL 9.8
CVE-2018-12601

There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other im…

Patch available
Fix from $2,300 2018-06-20
Debian Linux HIGH 8.8
CVE-2018-10841

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-…

Fix: 4.1.8+
Fix from $1,950 2018-06-20
Debian Linux HIGH 7.5
CVE-2018-10811EPSS 6%

strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

Fix: 5.6.3+
Fix from $1,950 2018-06-19
Debian Linux HIGH 8.8
CVE-2018-12565

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote …

Fix: after 2018.4
Fix from $1,950 2018-06-19
Debian Linux MEDIUM 6.5
CVE-2018-12564

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that wil…

Fix: 2018.5.post1+
Fix from $1,600 2018-06-19
Debian Linux HIGH 7.0
CVE-2018-12029

A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard pass…

Fix: 5.3.2+
Fix from $1,950 2018-06-17
Debian Linux MEDIUM 5.5
CVE-2018-12495

The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove…

No fix yet
Fix from $1,600 2018-06-15
Debian Linux MEDIUM 6.5
CVE-2018-12458

An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violati…

Patch available
Fix from $1,600 2018-06-15
Debian Linux MEDIUM 5.9
CVE-2018-10850

389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a cras…

Patch available
Fix from $1,600 2018-06-13
Debian Linux HIGH 8.8
CVE-2018-12264

Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.…

No fix yet
Fix from $1,950 2018-06-13
Debian Linux HIGH 8.8
CVE-2018-12265

Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.

No fix yet
Fix from $1,950 2018-06-13
Debian Linux HIGH 7.5
CVE-2018-0496

Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allo…

Fix: 3.14+
Fix from $1,950 2018-06-12
Debian Linux HIGH 7.5
CVE-2018-12249

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported i…

Patch available
Fix from $1,950 2018-06-12
Debian Linux MEDIUM 5.3
CVE-2018-12227

An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert bef…

Fix: 13.21.1 / 14.7.7+
Fix from $1,600 2018-06-12
Debian Linux HIGH 8.1
CVE-2018-5178

A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requi…

Fix: 52.8.0+
Fix from $1,950 2018-06-11