Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2018-0489

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatu…

Fix: 1.6.4 / 6.7.2+
Fix from $1,600 2018-02-27
Debian Linux HIGH 7.5
CVE-2018-7490EPSS 69%

uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

Fix: 2.0.17+
Fix from $1,950 2018-02-26
Debian Linux CRITICAL 9.8
CVE-2018-7489EPSS 20%

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an in…

Fix: 2.7.9.3 / 2.8.11.1+
Fix from $2,300 2018-02-26
Debian Linux HIGH 7.8
CVE-2018-7487

There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or poss…

No fix yet
Fix from $1,950 2018-02-26
Debian Linux MEDIUM 6.5
CVE-2018-7456

A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0a…

Patch available
Fix from $1,600 2018-02-24
Debian Linux MEDIUM 6.5
CVE-2018-7443

The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows r…

No fix yet
Fix from $1,600 2018-02-23
Debian Linux CRITICAL 9.8
CVE-2018-7440

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo…

Fix: after 1.75.3
Fix from $2,300 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7435

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7436

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7437

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7438

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7439

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 7.5
CVE-2018-7284EPSS 58%

A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.1…

Fix: after 15.2.1
Fix from $1,950 2018-02-22
Debian Linux MEDIUM 6.5
CVE-2018-7286EPSS 38%

An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pj…

Fix: after 15.2.1
Fix from $1,600 2018-02-22
Debian Linux MEDIUM 5.9
CVE-2015-5314

The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough fo…

Fix: 2.6+
Fix from $1,600 2018-02-21
Debian Linux MEDIUM 5.9
CVE-2015-5315

The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for …

Fix: 2.6+
Fix from $1,600 2018-02-21
Debian Linux MEDIUM 5.9
CVE-2015-5316

The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configurat…

Fix: 2.6+
Fix from $1,600 2018-02-21
Debian Linux HIGH 7.8
CVE-2018-7253

The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buff…

Patch available
Fix from $1,950 2018-02-19
Debian Linux HIGH 7.8
CVE-2018-7254EPSS 10%

The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-…

Patch available
Fix from $1,950 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2017-7375

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…

Fix: after 2.9.4
Fix from $2,300 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2017-7376EPSS 23%

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

Fix: 2.9.5+
Fix from $2,300 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2018-7225EPSS 6%

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to a…

No fix yet
Fix from $2,300 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2018-5379EPSS 38%

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a…

Fix: after 1.2.2
Fix from $2,300 2018-02-19
Debian Linux MEDIUM 5.9
CVE-2018-5378EPSS 74%

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is i…

Fix: after 1.2.2
Fix from $1,600 2018-02-19
Debian Linux HIGH 7.5
CVE-2017-18190

A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP c…

Fix: 2.2.2+
Fix from $1,950 2018-02-16
Debian Linux CRITICAL 9.8
CVE-2018-7186

Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a…

Fix: 1.75.3+
Fix from $2,300 2018-02-16
Debian Linux CRITICAL 9.8
CVE-2018-7053

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected orde…

Fix: 1.0.7+
Fix from $2,300 2018-02-15
Debian Linux HIGH 7.5
CVE-2018-7050

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.

Fix: 1.0.7+
Fix from $1,950 2018-02-15
Debian Linux HIGH 7.5
CVE-2018-7051

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme str…

Fix: 1.0.7+
Fix from $1,950 2018-02-15
Debian Linux HIGH 7.5
CVE-2017-18189EPSS 5%

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a …

Fix: after 14.4.2
Fix from $1,950 2018-02-15