Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.1
CVE-2017-8811

The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling…

Fix: after 1.27.3
Fix from $1,600 2017-11-15
Debian Linux MEDIUM 5.3
CVE-2017-8812

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attr…

Fix: after 1.27.3
Fix from $1,600 2017-11-15
Debian Linux HIGH 7.8
CVE-2017-16651 KEVEPSS 37%

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, i…

Fix: after 1.1.9
Fix from $1,950 2017-11-09
Debian Linux HIGH 8.8
CVE-2017-16669

coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or poss…

Patch available
Fix from $1,950 2017-11-09
Debian Linux HIGH 8.8
CVE-2017-15672

The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via …

Fix: after 3.3.4
Fix from $1,950 2017-11-06
Debian Linux HIGH 8.8
CVE-2017-16352EPSS 15%

GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Descri…

No fix yet
Fix from $1,950 2017-11-01
Debian Linux MEDIUM 6.5
CVE-2017-16353EPSS 14%

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil…

No fix yet
Fix from $1,600 2017-11-01
Debian Linux CRITICAL 9.1
CVE-2017-1000257EPSS 6%

An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl woul…

Fix: after 7.56.0
Fix from $2,300 2017-10-31
Debian Linux HIGH 7.5
CVE-2017-16227EPSS 19%

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT…

Fix: after 1.2.1
Fix from $1,950 2017-10-29
Debian Linux MEDIUM 5.5
CVE-2017-15953

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.

Patch available
Fix from $1,600 2017-10-28
Debian Linux MEDIUM 5.5
CVE-2017-15954

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processin…

Patch available
Fix from $1,600 2017-10-28
Debian Linux MEDIUM 5.5
CVE-2017-15955

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a ma…

Patch available
Fix from $1,600 2017-10-28
Debian Linux HIGH 8.8
CVE-2017-13089EPSS 80%

The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget b…

Fix: after 1.19.1
Fix from $1,950 2017-10-27
Debian Linux HIGH 8.8
CVE-2017-13090EPSS 37%

The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser …

Fix: after 1.19.1
Fix from $1,950 2017-10-27
Debian Linux HIGH 8.8
CVE-2017-15930

In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelP…

Patch available
Fix from $1,950 2017-10-27
Debian Linux HIGH 7.8
CVE-2017-15924

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration req…

Patch available
Fix from $1,950 2017-10-27
Debian Linux MEDIUM 6.5
CVE-2017-5094

Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacke…

Fix: 60.0.3112.78+
Fix from $1,600 2017-10-27
Debian Linux MEDIUM 5.3
CVE-2017-15906

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers …

Fix: 7.6+
Fix from $1,600 2017-10-26
Debian Linux MEDIUM 5.5
CVE-2017-15873

The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access vio…

Patch available
Fix from $1,600 2017-10-24
Debian Linux HIGH 7.5
CVE-2017-15721

In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue…

Fix: after 1.0.4
Fix from $1,950 2017-10-22
Debian Linux HIGH 7.5
CVE-2017-15723

In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.

Fix: after 1.0.4
Fix from $1,950 2017-10-22
Debian Linux MEDIUM 5.9
CVE-2017-15722

In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.

Fix: after 1.0.4
Fix from $1,600 2017-10-22
Debian Linux HIGH 7.5
CVE-2015-5177EPSS 6%

Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service…

Patch available
Fix from $1,950 2017-10-22
Debian Linux HIGH 7.8
CVE-2013-6049

apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors.

Mitigation only
Fix from $1,950 2017-10-20
Debian Linux MEDIUM 5.5
CVE-2017-15642

In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.

Mitigation only
Fix from $1,600 2017-10-19
Debian Linux MEDIUM 5.3
CVE-2017-10347

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u…

Patch available
Fix from $1,600 2017-10-19
Debian Linux CRITICAL 9.6
CVE-2017-10285

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u1…

Patch available
Fix from $2,300 2017-10-19
Debian Linux MEDIUM 5.3
CVE-2017-10281

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affect…

Patch available
Fix from $1,600 2017-10-19
Debian Linux MEDIUM 6.8
CVE-2017-10274

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u15…

Patch available
Fix from $1,600 2017-10-19
Debian Linux MEDIUM 6.5
CVE-2015-1239

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to ca…

Fix: 2.1.1+
Fix from $1,600 2017-10-18