Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.0
CVE-2018-5683

The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by…

Patch available
Fix from $1,600 2018-01-23
Debian Linux MEDIUM 6.1
CVE-2018-5950

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a …

Patch available
Fix from $1,600 2018-01-23
Debian Linux MEDIUM 5.3
CVE-2017-15105

A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be u…

Fix: 1.6.8+
Fix from $1,600 2018-01-23
Debian Linux HIGH 7.5
CVE-2018-6003

An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder lea…

Fix: after 4.12
Fix from $1,950 2018-01-22
Debian Linux HIGH 8.1
CVE-2018-5968EPSS 7%

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…

Fix: 2.6.7.3 / 2.7.9.2+
Fix from $1,950 2018-01-22
Debian Linux HIGH 7.5
CVE-2016-10708EPSS 16%

sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NE…

Fix: 7.4+
Fix from $1,950 2018-01-21
Debian Linux HIGH 7.8
CVE-2017-15108

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the …

Fix: after 0.17.0
Fix from $1,950 2018-01-20
Debian Linux MEDIUM 6.5
CVE-2018-5784

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this v…

Patch available
Fix from $1,600 2018-01-19
Debian Linux MEDIUM 6.5
CVE-2018-5785

In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote a…

No fix yet
Fix from $1,600 2018-01-19
Debian Linux MEDIUM 5.5
CVE-2018-5786

In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could le…

Patch available
Fix from $1,600 2018-01-19
Debian Linux MEDIUM 6.5
CVE-2017-12197

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di…

Fix: after 1.8
Fix from $1,600 2018-01-18
Debian Linux HIGH 7.5
CVE-2018-5764EPSS 6%

The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attacker…

Fix: 3.1.3+
Fix from $1,950 2018-01-17
Debian Linux MEDIUM 5.5
CVE-2018-5747

In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerabi…

No fix yet
Fix from $1,600 2018-01-17
Debian Linux CRITICAL 9.6
CVE-2018-5704

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attacker…

Patch available
Fix from $2,300 2018-01-16
Debian Linux HIGH 8.8
CVE-2018-5702EPSS 12%

Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote att…

Fix: after 2.92
Fix from $1,950 2018-01-15
Debian Linux MEDIUM 6.5
CVE-2018-5685

In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage…

Patch available
Fix from $1,600 2018-01-14
Debian Linux MEDIUM 5.5
CVE-2018-5686

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not co…

No fix yet
Fix from $1,600 2018-01-14
Debian Linux MEDIUM 6.5
CVE-2018-0486

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signature…

Fix: 1.6.3+
Fix from $1,600 2018-01-13
Debian Linux HIGH 7.5
CVE-2017-13194

A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android …

Patch available
Fix from $1,950 2018-01-12
Debian Linux CRITICAL 9.8
CVE-2017-17485EPSS 50%

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…

Fix: 2.6.7.3 / 2.7.9.2+
Fix from $2,300 2018-01-10
Debian Linux HIGH 8.8
CVE-2017-18026

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which …

Fix: 3.2.9 / 3.3.6+
Fix from $1,950 2018-01-10
Debian Linux CRITICAL 9.8
CVE-2015-2320

The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

Fix: 3.12.1+
Fix from $2,300 2018-01-08
Debian Linux HIGH 8.1
CVE-2015-2318

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by le…

Fix: 3.12.1+
Fix from $1,950 2018-01-08
Debian Linux MEDIUM 6.5
CVE-2018-5294

In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers coul…

Mitigation only
Fix from $1,600 2018-01-08
Debian Linux MEDIUM 5.5
CVE-2018-5268

In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing …

No fix yet
Fix from $1,600 2018-01-08
Debian Linux MEDIUM 5.5
CVE-2018-5269

In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.

No fix yet
Fix from $1,600 2018-01-08
Debian Linux CRITICAL 9.8
CVE-2018-5206

When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.

Fix: 1.0.6+
Fix from $2,300 2018-01-06
Debian Linux CRITICAL 9.8
CVE-2018-5208

In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.

Fix: 1.0.6+
Fix from $2,300 2018-01-06
Debian Linux HIGH 7.5
CVE-2018-5205

When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.

Fix: 1.0.6+
Fix from $1,950 2018-01-06
Debian Linux HIGH 7.5
CVE-2018-5207

When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.

Fix: 1.0.6+
Fix from $1,950 2018-01-06