Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2020-36179EPSS 21% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common… Debian Linux Patch available Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36180EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux Patch available Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36182EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36184EPSS 10% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux Patch available Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36185EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36186EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36187EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36188EPSS 11% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36189 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36181EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux Patch available Fix from $1,9502021-01-06 HIGH 7.8 CVE-2020-27844 A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg dur… Debian Linux 2.4.0+ Fix from $1,9502021-01-05 HIGH 7.5 CVE-2020-25275 Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain … Debian Linux 2.3.13+ Fix from $1,9502021-01-04 MEDIUM 6.8 CVE-2020-24386 An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled par… Debian Linux 2.3.13+ Fix from $1,6002021-01-04 HIGH 7.5 CVE-2020-35965 decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operatio… Debian Linux 4.4+ Fix from $1,9502021-01-04 CRITICAL 9.8 CVE-2020-12658 gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment s… Debian Linux 0.8.3+ Fix from $2,3002020-12-31 MEDIUM 5.3 CVE-2019-15523 An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_… Debian Linux after 2.0 Fix from $1,6002020-12-30 MEDIUM 6.1 CVE-2020-35738 WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-… Debian Linux Patch available Fix from $1,6002020-12-28 HIGH 8.1 CVE-2020-35728EPSS 13% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502020-12-27 HIGH 7.0 CVE-2020-28169 The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account… Debian Linux 2020-12-18+ Fix from $1,9502020-12-24 CRITICAL 9.8 CVE-2020-35605 The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing sp… Debian Linux 0.19.3+ Fix from $2,3002020-12-21 HIGH 7.5 CVE-2020-35573 srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address. Debian Linux 1.10+ Fix from $1,9502020-12-20 HIGH 7.5 CVE-2020-35475 In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits… Debian Linux 1.35.1+ Fix from $1,9502020-12-18 MEDIUM 6.1 CVE-2020-35479 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, t… Debian Linux 1.35.1+ Fix from $1,6002020-12-18 MEDIUM 5.3 CVE-2020-35477 MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main … Debian Linux 1.35.1+ Fix from $1,6002020-12-18 MEDIUM 5.3 CVE-2020-35480 An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hi… Debian Linux 1.35.1+ Fix from $1,6002020-12-18 HIGH 8.1 CVE-2020-35490EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux 2.9.10.8+ Fix from $1,9502020-12-17 HIGH 8.1 CVE-2020-35491EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux 2.9.10.8+ Fix from $1,9502020-12-17 HIGH 7.5 CVE-2020-29361 An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit li… Debian Linux after 0.23.21 Fix from $1,9502020-12-16 HIGH 7.5 CVE-2020-29363 An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit serve… Debian Linux 0.23.22+ Fix from $1,9502020-12-16 HIGH 8.8 CVE-2020-29481 An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not r… Debian Linux after 4.14.0 Fix from $1,9502020-12-15