Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2017-12105

An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c applies a particular object modifier to a Mes…

No fix yet
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.1
CVE-2017-14450

A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.8
CVE-2017-12081

An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open-source 3d creation suite v2.78c. A specially cra…

No fix yet
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.8
CVE-2017-12082

An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file wit…

No fix yet
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.8
CVE-2017-12086

An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A speciall…

No fix yet
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.5
CVE-2017-7651EPSS 5%

In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. …

Fix: after 1.4.14
Fix from $1,950 2018-04-24
Debian Linux MEDIUM 5.5
CVE-2016-9601

ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image functio…

Fix: 9.21+
Fix from $1,600 2018-04-24
Debian Linux CRITICAL 9.8
CVE-2017-17833

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or …

Patch available
Fix from $2,300 2018-04-23
Debian Linux MEDIUM 5.5
CVE-2018-10289

In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerabi…

No fix yet
Fix from $1,600 2018-04-22
Debian Linux HIGH 7.0
CVE-2017-2825

In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database write…

Fix: after 2.4.8
Fix from $1,950 2018-04-20
Debian Linux HIGH 7.5
CVE-2014-10073

The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is und…

Fix: 1.1.4+
Fix from $1,950 2018-04-20
Debian Linux HIGH 7.5
CVE-2018-1000164

gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in …

No fix yet
Fix from $1,950 2018-04-18
Debian Linux CRITICAL 9.8
CVE-2018-10191

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of de…

Fix: after 1.4.0
Fix from $2,300 2018-04-17
Debian Linux CRITICAL 9.8
CVE-2018-6797EPSS 7%

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes w…

Fix: after 5.26
Fix from $2,300 2018-04-17
Debian Linux CRITICAL 9.8
CVE-2018-6913EPSS 11%

Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item c…

Fix: 5.26.2+
Fix from $2,300 2018-04-17
Debian Linux HIGH 7.5
CVE-2018-6798

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and…

Fix: after 5.26
Fix from $1,950 2018-04-17
Debian Linux HIGH 7.8
CVE-2018-10119

sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, wh…

Fix: 5.4.5.1 / 6.0.1.1+
Fix from $1,950 2018-04-16
Debian Linux HIGH 7.8
CVE-2018-10120

The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a custo…

Fix: 5.4.6.1 / 6.0.2.1+
Fix from $1,950 2018-04-16
Debian Linux CRITICAL 9.8
CVE-2017-0359

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

Fix: 77+
Fix from $2,300 2018-04-13
Debian Linux CRITICAL 9.8
CVE-2017-0372EPSS 11%

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Fix: after 1.23.15
Fix from $2,300 2018-04-13
Debian Linux HIGH 8.8
CVE-2017-0362

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.

Fix: 1.27.2 / 1.28.1+
Fix from $1,950 2018-04-13
Debian Linux HIGH 8.8
CVE-2017-0367

Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp direct…

Fix: 1.27.2 / 1.28.1+
Fix from $1,950 2018-04-13
Debian Linux HIGH 7.8
CVE-2017-0361

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.

Fix: 1.27.2 / 1.28.1+
Fix from $1,950 2018-04-13
Debian Linux MEDIUM 6.5
CVE-2017-0369

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 6.1
CVE-2017-0363

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 6.1
CVE-2017-0364

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 5.4
CVE-2017-0366

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2017-0368

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2017-0370

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link par…

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux CRITICAL 9.8
CVE-2017-0356

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker …

Fix: 3.20170111+
Fix from $2,300 2018-04-13