Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2017-14733

ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2017-09-25
Debian Linux MEDIUM 6.1
CVE-2015-6748

Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.

Fix: 1.8.3+
Fix from $1,600 2017-09-25
Debian Linux HIGH 8.8
CVE-2017-14160

The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and …

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux HIGH 8.1
CVE-2017-14245

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux HIGH 8.1
CVE-2017-14246

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux CRITICAL 9.8
CVE-2017-14632EPSS 6%

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…

Mitigation only
Fix from $2,300 2017-09-21
Debian Linux MEDIUM 6.5
CVE-2017-14633

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…

Mitigation only
Fix from $1,600 2017-09-21
Debian Linux MEDIUM 6.5
CVE-2017-14634

In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio…

Mitigation only
Fix from $1,600 2017-09-21
Debian Linux HIGH 8.8
CVE-2015-5395

Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.

Fix: 3.1.0+
Fix from $1,950 2017-09-20
Debian Linux MEDIUM 6.5
CVE-2017-14604

GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .de…

Fix: 3.23.90+
Fix from $1,600 2017-09-20
Debian Linux MEDIUM 6.5
CVE-2017-14528

The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply …

No fix yet
Fix from $1,600 2017-09-18
Debian Linux MEDIUM 6.5
CVE-2017-14504

ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading to a NULL Pointer D…

Patch available
Fix from $1,600 2017-09-17
Debian Linux HIGH 8.8
CVE-2017-14482

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-dis…

Fix: after 25.2
Fix from $1,950 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13687

The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13725

The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13024

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13028

The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13004

The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13020

The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12896

The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12899

The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12902

The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12987

The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux HIGH 8.8
CVE-2017-2816

An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write…

No fix yet
Fix from $1,950 2017-09-13
Debian Linux MEDIUM 6.5
CVE-2017-14314

Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDash…

Patch available
Fix from $1,600 2017-09-12
Debian Linux MEDIUM 6.5
CVE-2017-7650

In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or rem…

Fix: 1.4.12+
Fix from $1,600 2017-09-11
Debian Linux MEDIUM 6.5
CVE-2017-14223

In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumpti…

Patch available
Fix from $1,600 2017-09-09
Debian Linux HIGH 8.8
CVE-2017-14167

Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (aka Quick Emulator) allows local guest OS users to execute arbitrary …

Fix: after 2.10.2
Fix from $1,950 2017-09-08
Debian Linux HIGH 7.5
CVE-2017-6362EPSS 5%

Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors relat…

Patch available
Fix from $1,950 2017-09-07
Debian Linux HIGH 8.8
CVE-2017-14169

In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, whi…

Patch available
Fix from $1,950 2017-09-07