Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2021-32491 A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to applicati… Debian Linux after 3.5.28 Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-32492 A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to appl… Debian Linux after 3.5.28 Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-32493 A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to applic… Debian Linux after 3.5.28 Fix from $1,9502021-06-24 MEDIUM 5.5 CVE-2021-27345 A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a c… Debian Linux Patch available Fix from $1,6002021-06-10 MEDIUM 5.5 CVE-2021-27347 Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed … Debian Linux Patch available Fix from $1,6002021-06-10 MEDIUM 5.5 CVE-2020-25467 A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) v… Debian Linux Patch available Fix from $1,6002021-06-10 HIGH 8.8 CVE-2020-24489 Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access. Debian Linux Mitigation only Fix from $1,9502021-06-09 MEDIUM 6.5 CVE-2021-0089 Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local acces… Debian Linux Mitigation only Fix from $1,6002021-06-09 MEDIUM 6.5 CVE-2020-24511 Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via l… Debian Linux 20210608+ Fix from $1,6002021-06-09 MEDIUM 6.5 CVE-2020-24513 Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information di… Debian Linux Mitigation only Fix from $1,6002021-06-09 CRITICAL 9.8 CVE-2021-33833 ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A … Debian Linux after 1.39 Fix from $2,3002021-06-09 MEDIUM 5.5 CVE-2021-26313 Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution… Debian Linux Mitigation only Fix from $1,6002021-06-09 MEDIUM 5.3 CVE-2021-28169EPSS 78% For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access pro… Debian Linux 9.4.41 / 10.0.3+ Fix from $1,6002021-06-09 HIGH 7.5 CVE-2021-33560 Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack again… Debian Linux 1.8.8 / 1.9.3+ Fix from $1,9502021-06-08 HIGH 7.5 CVE-2021-28091 Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. Debian Linux 2.7.0+ Fix from $1,9502021-06-04 HIGH 7.5 CVE-2021-33054 SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network ac… Debian Linux 2.4.1 / 5.1.1+ Fix from $1,9502021-06-04 MEDIUM 6.5 CVE-2020-22054 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c. Debian Linux No fix yet Fix from $1,6002021-06-02 HIGH 8.8 CVE-2015-1877 The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which all… Debian Linux Patch available Fix from $1,9502021-06-02 MEDIUM 6.5 CVE-2020-22046 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c. Debian Linux No fix yet Fix from $1,6002021-06-02 MEDIUM 6.5 CVE-2020-22048 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c. Debian Linux No fix yet Fix from $1,6002021-06-02 MEDIUM 6.5 CVE-2020-22049 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c. Debian Linux No fix yet Fix from $1,6002021-06-02 MEDIUM 5.5 CVE-2021-3468 A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is no… Debian Linux after 0.8 Fix from $1,6002021-06-02 MEDIUM 6.5 CVE-2019-12067 The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_… Debian Linux Patch available Fix from $1,6002021-06-02 HIGH 8.2 CVE-2021-3546 An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The … Debian Linux after 6.0.0 Fix from $1,9502021-06-02 MEDIUM 6.5 CVE-2021-3544 Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contr… Debian Linux after 6.0.0 Fix from $1,6002021-06-02 MEDIUM 6.5 CVE-2021-3545 An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. T… Debian Linux after 6.0.0 Fix from $1,6002021-06-02 HIGH 7.1 CVE-2018-10195 lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size… Debian Linux after 0.12.20 Fix from $1,9502021-06-02 MEDIUM 6.5 CVE-2020-22044 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c. Debian Linux Patch available Fix from $1,6002021-06-01 MEDIUM 6.5 CVE-2020-22037 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c. Debian Linux Patch available Fix from $1,6002021-06-01 MEDIUM 6.5 CVE-2020-22041 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc. Debian Linux No fix yet Fix from $1,6002021-06-01