Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2017-18187

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity…

Fix: 2.7.0+
Fix from $2,300 2018-02-14
Debian Linux CRITICAL 9.8
CVE-2018-0487

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ov…

Fix: 1.3.22 / 2.1.10+
Fix from $2,300 2018-02-13
Debian Linux CRITICAL 9.8
CVE-2018-0488

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute a…

Fix: 1.3.22 / 2.1.10+
Fix from $2,300 2018-02-13
Debian Linux HIGH 8.8
CVE-2018-1000041

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can…

Fix: 2.41.2+
Fix from $1,950 2018-02-09
Debian Linux HIGH 7.8
CVE-2018-1000051

Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This a…

Patch available
Fix from $1,950 2018-02-09
Debian Linux HIGH 7.5
CVE-2018-1000024EPSS 8%

The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ES…

Fix: after 4.0.22
Fix from $1,950 2018-02-09
Debian Linux HIGH 7.5
CVE-2018-1000027EPSS 13%

The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Resp…

Fix: 4.0.23+
Fix from $1,950 2018-02-09
Debian Linux CRITICAL 9.8
CVE-2018-6871EPSS 23%

LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.…

Patch available
Fix from $2,300 2018-02-09
Debian Linux MEDIUM 6.5
CVE-2018-6869

In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attacker…

Patch available
Fix from $1,600 2018-02-09
Debian Linux CRITICAL 9.8
CVE-2018-6789 KEVEPSS 82%

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may h…

Fix: 4.90.1+
Fix from $2,300 2018-02-08
Debian Linux HIGH 8.8
CVE-2018-6799

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap ove…

Fix: 1.3.28+
Fix from $1,950 2018-02-07
Debian Linux MEDIUM 5.3
CVE-2018-6794EPSS 24%

Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow…

Fix: 4.0.4+
Fix from $1,600 2018-02-07
Debian Linux MEDIUM 6.8
CVE-2018-6791

An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $(…

Fix: 5.12.0+
Fix from $1,600 2018-02-07
Debian Linux HIGH 7.8
CVE-2018-6767

A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-o…

Patch available
Fix from $1,950 2018-02-06
Debian Linux CRITICAL 9.8
CVE-2017-15095EPSS 8%

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo…

Fix: 2.6.7.2 / 2.7.9.2+
Fix from $2,300 2018-02-06
Debian Linux CRITICAL 9.8
CVE-2017-7525EPSS 38%

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user …

Fix: 2.6.7.1 / 2.7.9.1+
Fix from $2,300 2018-02-06
Debian Linux MEDIUM 6.5
CVE-2018-6621

The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) v…

Fix: after 3.2
Fix from $1,600 2018-02-05
Debian Linux MEDIUM 5.5
CVE-2018-6616

In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerabili…

No fix yet
Fix from $1,600 2018-02-04
Debian Linux CRITICAL 9.1
CVE-2018-6596

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al…

Fix: 1.2.1+
Fix from $2,300 2018-02-03
Debian Linux HIGH 8.6
CVE-2017-18123

The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download…

Fix: after 2017-02-19e
Fix from $1,950 2018-02-03
Debian Linux HIGH 7.5
CVE-2018-6594

lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive informati…

Fix: after 2.6.1
Fix from $1,950 2018-02-03
Debian Linux HIGH 8.1
CVE-2017-18122

A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as v…

Fix: after 1.14.16
Fix from $1,950 2018-02-02
Debian Linux MEDIUM 6.1
CVE-2017-18121

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that cou…

Fix: after 1.14.15
Fix from $1,600 2018-02-02
Debian Linux MEDIUM 5.5
CVE-2018-6544

pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which …

No fix yet
Fix from $1,600 2018-02-02
Debian Linux CRITICAL 9.8
CVE-2018-6521

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. T…

Fix: 1.15.2+
Fix from $2,300 2018-02-02
Debian Linux HIGH 7.5
CVE-2018-6519

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for…

Fix: 1.10.4 / 2.3.5+
Fix from $1,950 2018-02-02
Debian Linux MEDIUM 5.5
CVE-2017-18043

Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).

Fix: after 2.10.1
Fix from $1,600 2018-01-31
Debian Linux HIGH 7.8
CVE-2018-5996

Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruption…

Fix: 18.00 / 18.0+
Fix from $1,950 2018-01-31
Debian Linux MEDIUM 5.3
CVE-2011-2902

zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, wh…

Fix: 3.02-19+
Fix from $1,600 2018-01-30
Debian Linux HIGH 7.8
CVE-2017-17969

Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a de…

Fix: 18.00 / 18.0+
Fix from $1,950 2018-01-30