Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2017-0357

A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

Fix: 2.1.1+
Fix from $2,300 2018-04-13
Debian Linux HIGH 7.8
CVE-2017-0358

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe…

Fix: after 2016.2.22
Fix from $1,950 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2016-9646

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572),…

Fix: 3.20161229+
Fix from $1,600 2018-04-13
Debian Linux HIGH 7.5
CVE-2018-1084

corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.

Fix: 2.4.4+
Fix from $1,950 2018-04-12
Debian Linux HIGH 7.5
CVE-2018-1086

pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th…

Mitigation only
Fix from $1,950 2018-04-12
Debian Linux MEDIUM 5.4
CVE-2018-10060

Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.p…

Fix: after 1.1.36
Fix from $1,600 2018-04-12
Debian Linux MEDIUM 5.4
CVE-2018-10061

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape funct…

Fix: after 1.1.36
Fix from $1,600 2018-04-12
Debian Linux MEDIUM 6.5
CVE-2018-10001

The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) …

Fix: after 3.4.2
Fix from $1,600 2018-04-11
Debian Linux HIGH 8.8
CVE-2018-3839

An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially…

No fix yet
Fix from $1,950 2018-04-10
Debian Linux MEDIUM 6.5
CVE-2018-3838

An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially cr…

No fix yet
Fix from $1,600 2018-04-10
Debian Linux MEDIUM 5.5
CVE-2018-3837

An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A s…

No fix yet
Fix from $1,600 2018-04-10
Debian Linux HIGH 7.5
CVE-2018-9988

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on inva…

Fix: 2.1.11 / 2.7.2+
Fix from $1,950 2018-04-10
Debian Linux HIGH 7.5
CVE-2018-9989

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid …

Fix: 2.1.11 / 2.7.2+
Fix from $1,950 2018-04-10
Debian Linux HIGH 8.8
CVE-2018-9846

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled …

Fix: after 1.3.5
Fix from $1,950 2018-04-07
Debian Linux MEDIUM 5.3
CVE-2018-9251

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via …

No fix yet
Fix from $1,600 2018-04-04
Debian Linux HIGH 7.5
CVE-2018-9240

ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash …

Fix: after 0.29
Fix from $1,950 2018-04-03
Debian Linux HIGH 7.2
CVE-2018-0493

remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a da…

Fix: 3.14+
Fix from $1,950 2018-04-03
Debian Linux HIGH 7.0
CVE-2018-0492

Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.

Fix: after 1.3.4
Fix from $1,950 2018-04-03
Debian Linux HIGH 8.8
CVE-2017-7000

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" c…

Fix: 10.3.2 / 10.12.5+
Fix from $1,950 2018-04-03
Debian Linux MEDIUM 6.5
CVE-2018-9132

libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to ca…

No fix yet
Fix from $1,600 2018-03-30
Debian Linux HIGH 7.5
CVE-2018-1064

libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor …

Fix: after 4.1.0
Fix from $1,950 2018-03-28
Debian Linux HIGH 8.8
CVE-2017-11509EPSS 6%

An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.

No fix yet
Fix from $1,950 2018-03-28
Debian Linux MEDIUM 6.1
CVE-2018-8048

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

Fix: 2.2.1+
Fix from $1,600 2018-03-27
Debian Linux HIGH 8.8
CVE-2018-8764

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for …

Fix: 6.3+
Fix from $1,950 2018-03-27
Debian Linux MEDIUM 6.1
CVE-2018-8763

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or th…

Fix: 6.3+
Fix from $1,600 2018-03-27
Debian Linux MEDIUM 6.5
CVE-2018-9018

In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability …

No fix yet
Fix from $1,600 2018-03-25
Debian Linux HIGH 8.8
CVE-2018-9009

In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.

No fix yet
Fix from $1,950 2018-03-25
Debian Linux MEDIUM 6.5
CVE-2018-8976

In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a c…

Patch available
Fix from $1,600 2018-03-25
Debian Linux CRITICAL 9.8
CVE-2018-1000140EPSS 10%

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result …

Patch available
Fix from $2,300 2018-03-23
Debian Linux HIGH 8.8
CVE-2018-8905

In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2p…

Patch available
Fix from $1,950 2018-03-22