Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2018-11214

An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fa…

No fix yet
Fix from $1,600 2018-05-16
Debian Linux MEDIUM 6.5
CVE-2018-10999

An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.

No fix yet
Fix from $1,600 2018-05-12
Debian Linux HIGH 8.8
CVE-2018-10982

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array…

Fix: after 4.10.1
Fix from $1,950 2018-05-10
Debian Linux MEDIUM 6.5
CVE-2018-10981

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations wher…

Fix: after 4.10.1
Fix from $1,600 2018-05-10
Debian Linux HIGH 8.8
CVE-2017-18266

The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER enviro…

Fix: 1.1.3+
Fix from $1,950 2018-05-10
Debian Linux MEDIUM 6.5
CVE-2018-10958

In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUnc…

No fix yet
Fix from $1,600 2018-05-10
Debian Linux MEDIUM 6.5
CVE-2018-10963

The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failu…

Fix: after 4.0.9
Fix from $1,600 2018-05-10
Debian Linux HIGH 7.5
CVE-2017-18265

Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions o…

Fix: 0.10.0+
Fix from $1,950 2018-05-09
Debian Linux HIGH 7.8
CVE-2018-8897EPSS 19%

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the developme…

Fix: 11.1+
Fix from $1,950 2018-05-08
Debian Linux CRITICAL 9.8
CVE-2018-1000178

A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datas…

Patch available
Fix from $2,300 2018-05-08
Debian Linux HIGH 7.5
CVE-2018-1000179

A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhand…

No fix yet
Fix from $1,950 2018-05-08
Debian Linux HIGH 7.8
CVE-2018-10380

kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

Fix: 5.12.6+
Fix from $1,950 2018-05-08
Debian Linux CRITICAL 9.8
CVE-2018-10771

Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (appli…

Fix: after 8.13.20
Fix from $2,300 2018-05-07
Debian Linux CRITICAL 9.8
CVE-2018-10753

Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service…

Fix: after 8.13.20
Fix from $2,300 2018-05-05
Debian Linux CRITICAL 9.8
CVE-2017-18264

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused …

Fix: 4.0.10.20+
Fix from $2,300 2018-05-01
Debian Linux HIGH 7.8
CVE-2018-10536

An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRi…

Fix: after 5.1.0
Fix from $1,950 2018-04-29
Debian Linux HIGH 7.8
CVE-2018-10537

An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWa…

Fix: after 5.1.0
Fix from $1,950 2018-04-29
Debian Linux MEDIUM 5.5
CVE-2018-10538

An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not v…

Fix: after 5.1.0
Fix from $1,600 2018-04-29
Debian Linux MEDIUM 5.5
CVE-2018-10539

An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c doe…

Fix: after 5.1.0
Fix from $1,600 2018-04-29
Debian Linux MEDIUM 5.5
CVE-2018-10540

An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does n…

Fix: after 5.1.0
Fix from $1,600 2018-04-29
Debian Linux MEDIUM 6.5
CVE-2018-10471

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor cr…

Fix: after 4.10.1
Fix from $1,600 2018-04-27
Debian Linux MEDIUM 5.6
CVE-2018-10472

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live i…

Fix: after 4.10.1
Fix from $1,600 2018-04-27
Debian Linux HIGH 8.8
CVE-2016-9602

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to…

Fix: 2.9+
Fix from $1,950 2018-04-26
Debian Linux HIGH 8.8
CVE-2018-10392

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial …

No fix yet
Fix from $1,950 2018-04-26
Debian Linux HIGH 7.5
CVE-2018-10393

bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.

Mitigation only
Fix from $1,950 2018-04-26
Debian Linux MEDIUM 5.5
CVE-2017-6888

An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory lea…

Fix: after 1.3.2
Fix from $1,600 2018-04-25
Debian Linux HIGH 7.5
CVE-2017-7652

In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the confi…

Fix: after 1.4.14
Fix from $1,950 2018-04-25
Debian Linux HIGH 8.8
CVE-2017-2923

An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file …

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 8.8
CVE-2017-2924

An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cau…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.8
CVE-2017-2901

An exploitable integer overflow exists in the IRIS loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially craf…

No fix yet
Fix from $1,950 2018-04-24