Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2018-5251

In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote…

No fix yet
Fix from $1,600 2018-01-05
Debian Linux HIGH 8.8
CVE-2018-5248

In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode fun…

No fix yet
Fix from $1,950 2018-01-05
Debian Linux MEDIUM 5.9
CVE-2017-1665

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly …

Mitigation only
Fix from $1,600 2018-01-04
Debian Linux CRITICAL 9.8
CVE-2017-1000487EPSS 6%

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

Fix: 3.0.16+
Fix from $2,300 2018-01-03
Debian Linux MEDIUM 6.5
CVE-2017-1000472

The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the …

Fix: 1.8+
Fix from $1,600 2018-01-03
Debian Linux MEDIUM 6.5
CVE-2017-1000476

ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a den…

Patch available
Fix from $1,600 2018-01-03
Debian Linux CRITICAL 9.8
CVE-2017-1000501

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthen…

Fix: after 7.6.0
Fix from $2,300 2018-01-03
Debian Linux HIGH 8.1
CVE-2017-1000433

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without k…

Fix: after 4.4.0
Fix from $1,950 2018-01-02
Debian Linux HIGH 8.8
CVE-2017-1000422

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential …

Fix: after 2.36.8
Fix from $1,950 2018-01-02
Debian Linux CRITICAL 9.8
CVE-2017-1000421

Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution

Fix: after 1.89
Fix from $2,300 2018-01-02
Debian Linux HIGH 8.8
CVE-2017-1000456

freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

Patch available
Fix from $1,950 2018-01-02
Debian Linux HIGH 8.8
CVE-2017-1000450

In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. …

Fix: after 3.3.0
Fix from $1,950 2018-01-02
Debian Linux MEDIUM 6.5
CVE-2017-1000445

ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service

Fix: 6.9.9-15+
Fix from $1,600 2018-01-02
Debian Linux MEDIUM 5.5
CVE-2017-18005

Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.

No fix yet
Fix from $1,600 2017-12-31
Debian Linux MEDIUM 6.5
CVE-2017-17760

OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.

Patch available
Fix from $1,600 2017-12-29
Debian Linux CRITICAL 9.8
CVE-2014-4914

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…

Fix: 1.12.7+
Fix from $2,300 2017-12-29
Debian Linux HIGH 8.8
CVE-2017-17912

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 8.8
CVE-2017-17913

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 8.8
CVE-2017-17915

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte bef…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.8
CVE-2017-17866

pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allow…

Fix: 1.12.0+
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.5
CVE-2017-17846

An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.5
CVE-2017-17847

An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment s…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.5
CVE-2017-17848

An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages becau…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.3
CVE-2017-17845

An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp)…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Debian Linux MEDIUM 6.5
CVE-2017-17844

An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacke…

Fix: 1.9.9+
Fix from $1,600 2017-12-27
Debian Linux MEDIUM 5.9
CVE-2017-17843

An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorr…

Fix: 1.9.9+
Fix from $1,600 2017-12-27
Debian Linux HIGH 8.8
CVE-2017-17476

Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remo…

Fix: 4.0.28 / 5.0.26+
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17786

In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-…

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17787

In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.

Patch available
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17789

In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.

Patch available
Fix from $1,950 2017-12-20