Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2017-15572

In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, b…

Fix: after 3.2.5
Fix from $1,950 2017-10-18
Debian Linux HIGH 7.5
CVE-2017-15576

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive info…

Fix: after 3.2.5
Fix from $1,950 2017-10-18
Debian Linux HIGH 7.5
CVE-2017-15577

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

Fix: after 3.2.5
Fix from $1,950 2017-10-18
Debian Linux HIGH 7.3
CVE-2017-15575

In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which …

Fix: after 3.2.5
Fix from $1,950 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15568

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a c…

Fix: after 3.2.7
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15569

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a craft…

Fix: after 3.2.7
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15570

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.

Fix: after 3.2.7
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15571

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.

Fix: after 3.2.7
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15573

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

Fix: after 3.2.5
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15574

In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

Fix: after 3.2.5
Fix from $1,600 2017-10-18
Debian Linux HIGH 8.8
CVE-2017-15565

In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.

No fix yet
Fix from $1,950 2017-10-17
Ftpsync CRITICAL 9.1
CVE-2017-8805

Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a…

Fix: after 20171016
Fix from $2,300 2017-10-17
Debian Linux HIGH 8.8
CVE-2015-7504

Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (insta…

Fix: after 2.4.1
Fix from $1,950 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15370

There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15371

There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15372

There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will le…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux HIGH 8.8
CVE-2017-2887

An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can c…

Mitigation only
Fix from $1,950 2017-10-11
Debian Linux CRITICAL 9.8
CVE-2017-0903EPSS 16%

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio…

Patch available
Fix from $2,300 2017-10-11
Debian Linux HIGH 8.8
CVE-2017-15238

ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.

Patch available
Fix from $1,950 2017-10-11
Debian Linux HIGH 7.8
CVE-2017-13723

In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing c…

Fix: after 1.19.3
Fix from $1,950 2017-10-10
Debian Linux CRITICAL 9.8
CVE-2017-1000116EPSS 6%

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

Fix: 4.3+
Fix from $2,300 2017-10-05
Debian Linux HIGH 7.5
CVE-2017-1000115

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

Fix: 4.3+
Fix from $1,950 2017-10-05
Debian Linux MEDIUM 6.5
CVE-2017-14994

ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted D…

Patch available
Fix from $1,600 2017-10-04
Debian Linux MEDIUM 6.5
CVE-2017-14997

GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTI…

Patch available
Fix from $1,600 2017-10-04
Debian Linux HIGH 7.5
CVE-2017-14975

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is n…

No fix yet
Fix from $1,950 2017-10-02
Debian Linux HIGH 7.5
CVE-2017-14976

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font d…

Patch available
Fix from $1,950 2017-10-02
Debian Linux HIGH 7.5
CVE-2017-14977

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of…

No fix yet
Fix from $1,950 2017-10-02
Debian Linux MEDIUM 5.5
CVE-2017-14926

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Debian Linux MEDIUM 5.5
CVE-2017-14928

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Debian Linux MEDIUM 5.5
CVE-2017-14737

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker …

Fix: after 1.10.16
Fix from $1,600 2017-09-26