Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2017-11104 Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key na… Debian Linux after 2.4.4 Fix from $1,6002017-07-08 CRITICAL 9.8 CVE-2016-4000EPSS 6% Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. Debian Linux Patch available Fix from $2,3002017-07-06 HIGH 7.5 CVE-2017-9524 The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a d… Debian Linux after 2.9.1 Fix from $1,9502017-07-06 HIGH 8.2 CVE-2017-2295 Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. … Debian Linux after 4.10.0 Fix from $1,9502017-07-05 HIGH 8.8 CVE-2017-9992 Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x bef… Debian Linux 2.8.12 / 3.0.8+ Fix from $1,9502017-06-28 HIGH 7.8 CVE-2017-9994 libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pi… Debian Linux 2.8.12 / 3.0.8+ Fix from $1,9502017-06-28 HIGH 7.5 CVE-2017-9993EPSS 16% FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filenam… Debian Linux 2.8.12 / 3.1.9+ Fix from $1,9502017-06-28 MEDIUM 6.5 CVE-2017-9988 The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NUL… Debian Linux No fix yet Fix from $1,6002017-06-28 MEDIUM 6.5 CVE-2017-9989 util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) at… Debian Linux No fix yet Fix from $1,6002017-06-28 MEDIUM 6.5 CVE-2017-9936EPSS 7% In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service att… Debian Linux No fix yet Fix from $1,6002017-06-26 MEDIUM 5.5 CVE-2017-9928 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service vi… Debian Linux Patch available Fix from $1,6002017-06-26 MEDIUM 5.5 CVE-2017-9929 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service v… Debian Linux Patch available Fix from $1,6002017-06-26 MEDIUM 5.5 CVE-2017-9868 In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic infor… Debian Linux after 1.4.12 Fix from $1,6002017-06-25 MEDIUM 5.5 CVE-2017-9865 The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over… Debian Linux Mitigation only Fix from $1,6002017-06-25 HIGH 7.8 CVE-2017-9776 Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of … Debian Linux after 0.55.0 Fix from $1,9502017-06-22 MEDIUM 6.5 CVE-2017-9775 Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) vi… Debian Linux after 0.55.0 Fix from $1,6002017-06-22 HIGH 7.8 CVE-2017-9780 In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example set… Debian Linux after 0.8.6 Fix from $1,9502017-06-21 MEDIUM 5.5 CVE-2017-9373 Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of ser… Debian Linux after 2.8.1.1 Fix from $1,6002017-06-16 MEDIUM 5.5 CVE-2017-9375 QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service … Debian Linux after 2.8.1.1 Fix from $1,6002017-06-16 MEDIUM 5.5 CVE-2017-9503 QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a… Debian Linux after 2.9.1 Fix from $1,6002017-06-16 HIGH 7.5 CVE-2017-9735EPSS 6% Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by obser… Debian Linux 9.2.22 / 9.3.20+ Fix from $1,9502017-06-16 HIGH 7.8 CVE-2017-4966 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb… Debian Linux Mitigation only Fix from $1,9502017-06-13 MEDIUM 6.1 CVE-2017-4965 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb… Debian Linux Mitigation only Fix from $1,6002017-06-13 MEDIUM 6.1 CVE-2017-4967 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb… Debian Linux Mitigation only Fix from $1,6002017-06-13 HIGH 8.8 CVE-2017-9324 In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable o… Debian Linux after 5.0.19 Fix from $1,9502017-06-12 HIGH 7.8 CVE-2017-9527 The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and applicati… Debian Linux after 1.2.0 Fix from $1,9502017-06-11 HIGH 7.5 CVE-2017-0376 The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_… Debian Linux 0.3.0.8+ Fix from $1,9502017-06-09 MEDIUM 6.7 CVE-2017-9525 In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to… Debian Linux after 3.0pl1-128. Fix from $1,6002017-06-09 HIGH 7.5 CVE-2017-9022 The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause … Debian Linux after 5.5.2 Fix from $1,9502017-06-08 MEDIUM 5.6 CVE-2017-9310 QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (inf… Debian Linux after 2.8.1.1 Fix from $1,6002017-06-08