Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2016-9079 KEVEPSS 87%

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting…

Fix: 45.5.1 / 50.0.2+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 6.1
CVE-2016-9895

Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerabili…

Fix: 45.6.0 / 50.1+
Fix from $1,600 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-7654

In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted …

Fix: after 1.4.15
Fix from $1,950 2018-06-05
Debian Linux MEDIUM 5.3
CVE-2017-7653

The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that…

Fix: after 1.4.15
Fix from $1,600 2018-06-05
Debian Linux CRITICAL 9.8
CVE-2018-11743

The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of serv…

Patch available
Fix from $2,300 2018-06-05
Debian Linux HIGH 7.5
CVE-2018-1000180

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically R…

Fix: after 1.59
Fix from $1,950 2018-06-05
Debian Linux MEDIUM 5.9
CVE-2016-1000345

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an…

Fix: after 1.55
Fix from $1,600 2018-06-04
Debian Linux HIGH 7.5
CVE-2016-1000342

In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible …

Fix: after 1.55
Fix from $1,950 2018-06-04
Debian Linux HIGH 7.5
CVE-2016-1000343

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If th…

Fix: after 1.55
Fix from $1,950 2018-06-04
Debian Linux MEDIUM 5.9
CVE-2016-1000341

In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely obse…

Fix: after 1.55
Fix from $1,600 2018-06-04
Debian Linux MEDIUM 5.3
CVE-2016-1000339

In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven ap…

Fix: after 1.55
Fix from $1,600 2018-06-04
Debian Linux MEDIUM 6.5
CVE-2018-5388

In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion an…

Fix: 5.6.3+
Fix from $1,600 2018-05-31
Debian Linux MEDIUM 5.3
CVE-2018-10995

SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).

Fix: after 17.02.10.1
Fix from $1,600 2018-05-30
Debian Linux MEDIUM 6.5
CVE-2018-11439

The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based bu…

No fix yet
Fix from $1,600 2018-05-30
Debian Linux HIGH 7.8
CVE-2018-11235EPSS 49%

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. Wi…

Fix: after 2.16.3
Fix from $1,950 2018-05-30
Debian Linux CRITICAL 9.8
CVE-2018-11531

Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.

No fix yet
Fix from $2,300 2018-05-29
Debian Linux MEDIUM 5.5
CVE-2018-11503

The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove…

Mitigation only
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 5.5
CVE-2018-11504

The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-re…

Mitigation only
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 6.5
CVE-2018-11496

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size vali…

No fix yet
Fix from $1,600 2018-05-26
Debian Linux HIGH 8.8
CVE-2018-11490

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer…

Fix: after 3.1.1
Fix from $1,950 2018-05-26
Debian Linux MEDIUM 5.5
CVE-2018-11468

The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer o…

No fix yet
Fix from $1,600 2018-05-25
Debian Linux CRITICAL 9.1
CVE-2018-1000301EPSS 6%

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl…

Fix: 7.2+
Fix from $2,300 2018-05-24
Debian Linux MEDIUM 5.5
CVE-2018-1000040

In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service …

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Debian Linux MEDIUM 5.5
CVE-2018-1000199

The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory …

Patch available
Fix from $1,600 2018-05-24
Debian Linux MEDIUM 5.5
CVE-2018-1000036

In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a craft…

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Debian Linux MEDIUM 5.5
CVE-2018-1000037

In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) vi…

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Debian Linux HIGH 7.5
CVE-2018-11319

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potent…

Fix: after 3.9.0
Fix from $1,950 2018-05-20
Debian Linux MEDIUM 6.5
CVE-2017-18273

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows at…

No fix yet
Fix from $1,600 2018-05-18
Debian Linux MEDIUM 6.5
CVE-2018-11212EPSS 5%

An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-…

Patch available
Fix from $1,600 2018-05-16
Debian Linux MEDIUM 6.5
CVE-2018-11213

An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation f…

No fix yet
Fix from $1,600 2018-05-16