Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2017-8820

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers…

Fix: 0.2.5.16 / 0.2.8.17+
Fix from $1,950 2017-12-03
Debian Linux HIGH 7.5
CVE-2017-8821

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can …

Fix: 0.2.5.16 / 0.2.8.17+
Fix from $1,950 2017-12-03
Debian Linux HIGH 7.5
CVE-2017-16612EPSS 5%

libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with program…

Fix: after 1.1.14
Fix from $1,950 2017-12-01
Debian Linux MEDIUM 5.5
CVE-2017-16611

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, w…

Fix: 1.5.4 / 2.0.3+
Fix from $1,600 2017-12-01
Debian Linux MEDIUM 5.5
CVE-2017-17087

fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group owners…

Fix: 8.0.1263+
Fix from $1,600 2017-12-01
Debian Linux HIGH 8.8
CVE-2017-14176EPSS 6%

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash chara…

Fix: after 2.7.0
Fix from $1,950 2017-11-27
Debian Linux HIGH 8.1
CVE-2017-8028

In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind…

Mitigation only
Fix from $1,950 2017-11-27
Debian Linux CRITICAL 9.8
CVE-2017-16943EPSS 47%

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of…

Patch available
Fix from $2,300 2017-11-25
Debian Linux HIGH 7.5
CVE-2017-16944EPSS 63%

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop an…

No fix yet
Fix from $1,950 2017-11-25
Debian Linux HIGH 8.4
CVE-2017-16927

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, wh…

Fix: after 0.9.4
Fix from $1,950 2017-11-23
Debian Linux HIGH 8.8
CVE-2017-16664

Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In t…

Fix: 3.3.20 / 4.0.26+
Fix from $1,950 2017-11-21
Debian Linux CRITICAL 9.8
CVE-2017-16613EPSS 8%

An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …

Fix: after 2.15.1
Fix from $2,300 2017-11-21
Debian Linux CRITICAL 9.8
CVE-2017-16840

The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorre…

Patch available
Fix from $2,300 2017-11-21
Debian Linux HIGH 7.8
CVE-2017-2896

An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a mem…

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 7.8
CVE-2017-2919

An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause …

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 7.1
CVE-2017-16899

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with…

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 8.8
CVE-2017-16544EPSS 6%

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames i…

Fix: after 1.27.2
Fix from $1,950 2017-11-20
Debian Linux CRITICAL 10.0
CVE-2017-16845

hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.

Fix: after 2.11.2
Fix from $2,300 2017-11-17
Debian Linux CRITICAL 9.8
CVE-2017-16872

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cse…

Fix: 2.7.1+
Fix from $2,300 2017-11-17
Debian Linux HIGH 7.8
CVE-2017-1000229

Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.

No fix yet
Fix from $1,950 2017-11-17
Debian Linux HIGH 8.1
CVE-2017-16852

shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly conf…

Fix: 2.6.1+
Fix from $1,950 2017-11-16
Debian Linux HIGH 8.1
CVE-2017-16853

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly co…

Fix: 2.6.1+
Fix from $1,950 2017-11-16
Debian Linux HIGH 8.8
CVE-2017-15864

In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database …

Fix: after 3.3.18
Fix from $1,950 2017-11-16
Debian Linux CRITICAL 9.1
CVE-2017-8807

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sen…

Fix: 4.1.9 / 5.2.1+
Fix from $2,300 2017-11-16
Debian Linux HIGH 7.5
CVE-2017-15923

Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing o…

Fix: 1.7.3+
Fix from $1,950 2017-11-15
Debian Linux CRITICAL 9.8
CVE-2017-8809EPSS 8%

api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.

Fix: after 1.27.3
Fix from $2,300 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-8810

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for fai…

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-8814

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a …

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-8815

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rul…

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Debian Linux MEDIUM 6.1
CVE-2017-8808

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sen…

Fix: after 1.27.3
Fix from $1,600 2017-11-15