Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2017-14166

libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar …

Patch available
Fix from $1,600 2017-09-06
Debian Linux HIGH 7.8
CVE-2017-2862

An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafte…

No fix yet
Fix from $1,950 2017-09-05
Debian Linux HIGH 7.8
CVE-2017-2870

An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially…

No fix yet
Fix from $1,950 2017-09-05
Debian Linux HIGH 8.8
CVE-2017-14151EPSS 5%

An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of…

Patch available
Fix from $1,950 2017-09-05
Debian Linux HIGH 8.8
CVE-2017-14152EPSS 5%

A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bou…

Patch available
Fix from $1,950 2017-09-05
Debian Linux HIGH 7.8
CVE-2017-1000083EPSS 51%

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via…

Fix: after 3.24.0
Fix from $1,950 2017-09-05
Debian Linux MEDIUM 6.5
CVE-2017-14136

OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image fi…

Patch available
Fix from $1,600 2017-09-04
Debian Linux MEDIUM 6.5
CVE-2017-14132

JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.90…

Patch available
Fix from $1,600 2017-09-04
Debian Linux CRITICAL 9.1
CVE-2017-14122

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.

Mitigation only
Fix from $2,300 2017-09-03
Debian Linux HIGH 7.5
CVE-2017-14120

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] a…

Mitigation only
Fix from $1,950 2017-09-03
Debian Linux MEDIUM 5.5
CVE-2017-14121

The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a craf…

Mitigation only
Fix from $1,600 2017-09-03
Debian Linux CRITICAL 9.8
CVE-2017-12873

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impact…

Fix: after 1.14.10
Fix from $2,300 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-12874

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature valid…

Patch available
Fix from $1,950 2017-09-01
Debian Linux MEDIUM 5.9
CVE-2017-12872

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote att…

Fix: after 1.14.11
Fix from $1,600 2017-09-01
Debian Linux MEDIUM 6.5
CVE-2017-14107

The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of servic…

Fix: 1.3.0+
Fix from $1,600 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-12869

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentica…

Fix: after 1.14.13
Fix from $1,950 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-13711

Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEM…

Fix: after 2.10.1
Fix from $1,950 2017-09-01
Debian Linux MEDIUM 5.5
CVE-2017-13672

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out…

Fix: after 2.10.2
Fix from $1,600 2017-09-01
Debian Linux CRITICAL 9.8
CVE-2017-0899EPSS 11%

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem…

Fix: after 2.6.12
Fix from $2,300 2017-08-31
Debian Linux HIGH 8.1
CVE-2017-0902

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to downlo…

Patch available
Fix from $1,950 2017-08-31
Debian Linux HIGH 7.5
CVE-2017-0900EPSS 8%

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clie…

Fix: after 2.6.12
Fix from $1,950 2017-08-31
Debian Linux HIGH 7.5
CVE-2017-0901EPSS 29%

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th…

Patch available
Fix from $1,950 2017-08-31
Debian Linux MEDIUM 6.1
CVE-2016-10510

Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or H…

Fix: after 3.3.5
Fix from $1,600 2017-08-31
Debian Linux CRITICAL 9.8
CVE-2017-14062

Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possib…

Fix: 2.0.4+
Fix from $2,300 2017-08-31
Debian Linux HIGH 8.8
CVE-2017-14039

A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an o…

Fix: 2.3.0+
Fix from $1,950 2017-08-30
Debian Linux HIGH 8.8
CVE-2017-14040

An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may l…

Patch available
Fix from $1,950 2017-08-30
Debian Linux HIGH 8.8
CVE-2017-14041EPSS 6%

A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bo…

Patch available
Fix from $1,950 2017-08-30
Debian Linux MEDIUM 6.5
CVE-2017-13768

Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial …

Fix: 6.9.9-11+
Fix from $1,600 2017-08-30
Debian Linux MEDIUM 6.5
CVE-2017-13775

GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory resources may be consum…

Patch available
Fix from $1,600 2017-08-30
Debian Linux MEDIUM 6.5
CVE-2017-13776

GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the re…

Patch available
Fix from $1,600 2017-08-30