Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2017-17788

In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.

Mitigation only
Fix from $1,600 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-17782

In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17784

In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling o…

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17785

In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.5
CVE-2017-17783

In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-17670

In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to…

Fix: after 2.2.8
Fix from $1,950 2017-12-15
Debian Linux HIGH 8.8
CVE-2017-17511

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17514

boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote …

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17515

etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might all…

Mitigation only
Fix from $1,950 2017-12-14
Tin HIGH 8.8
CVE-2017-17520

tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might a…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17527

delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the BROWSER environment variable…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux MEDIUM 5.9
CVE-2017-1000385EPSS 22%

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decry…

Mitigation only
Fix from $1,600 2017-12-12
Debian Linux HIGH 8.8
CVE-2017-17500

ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux HIGH 8.8
CVE-2017-17501

WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux HIGH 8.8
CVE-2017-17502

ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux HIGH 8.8
CVE-2017-17503

ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux CRITICAL 9.8
CVE-2017-17480EPSS 5%

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou…

Mitigation only
Fix from $2,300 2017-12-08
Debian Linux MEDIUM 6.5
CVE-2017-16854

In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a custo…

Fix: after 6.0.1
Fix from $1,600 2017-12-08
Debian Linux HIGH 8.8
CVE-2017-16921EPSS 20%

In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged …

Patch available
Fix from $1,950 2017-12-08
Debian Linux CRITICAL 9.8
CVE-2017-17458EPSS 6%

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a …

Fix: 4.4.1+
Fix from $2,300 2017-12-07
Debian Linux MEDIUM 6.5
CVE-2017-17381

The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by uns…

Fix: after 2.10.2
Fix from $1,600 2017-12-07
Debian Linux HIGH 7.5
CVE-2017-17439

In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for c…

Fix: after 7.4.0
Fix from $1,950 2017-12-06
Debian Linux CRITICAL 9.8
CVE-2017-17434

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (i…

Fix: after 3.1.2
Fix from $2,300 2017-12-06
Debian Linux HIGH 7.5
CVE-2017-17432

OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or appl…

Fix: 1.6.22+
Fix from $1,950 2017-12-06
Most CRITICAL 9.8
CVE-2016-1253

The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote …

Fix: 5.0.0a-2.2 / 5.0.0a-2.3+
Fix from $2,300 2017-12-05
Postgresql Common HIGH 7.8
CVE-2016-1255

The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befo…

Patch available
Fix from $1,950 2017-12-05
Debian Linux HIGH 7.5
CVE-2016-1254

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

Fix: 0.2.8.12+
Fix from $1,950 2017-12-05
Advanced Package Tool MEDIUM 5.9
CVE-2016-1252EPSS 7%

The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 L…

Fix: 1.0.9.8.4+
Fix from $1,600 2017-12-05
Debian Linux HIGH 8.1
CVE-2017-8823

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-a…

Fix: 0.2.5.16 / 0.2.8.17+
Fix from $1,950 2017-12-03
Debian Linux HIGH 7.5
CVE-2017-8819

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache…

Fix: 0.2.5.16 / 0.2.8.17+
Fix from $1,950 2017-12-03