Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-29483 An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest viol… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.0 CVE-2020-29482 An issue was discovered in Xen through 4.14.x. A guest may access xenstore paths via absolute paths containing a full pathname, or via a relative pat… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.0 CVE-2020-29484 An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore mes… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.0 CVE-2020-29486 An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node owne… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-29485 An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest … Debian Linux after 4.14.0 Fix from $1,6002020-12-15 HIGH 8.8 CVE-2020-29479 An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for t… Debian Linux after 4.14.0 Fix from $1,9502020-12-15 MEDIUM 6.5 CVE-2020-29568 An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If t… Debian Linux after 4.14.1 Fix from $1,6002020-12-15 MEDIUM 6.2 CVE-2020-29570 An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the contro… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.2 CVE-2020-29571 An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the … Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-29566 An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. T… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 HIGH 7.5 CVE-2020-8231 Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. Debian Linux 1.0.1.1 / 8.2.12+ Fix from $1,9502020-12-14 HIGH 7.5 CVE-2020-8285EPSS 10% curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. Debian Linux 7.74.0+ Fix from $1,9502020-12-14 MEDIUM 5.3 CVE-2020-35176 In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to on… Debian Linux after 7.8 Fix from $1,6002020-12-12 CRITICAL 9.8 CVE-2020-7788 This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pol… Debian Linux 1.3.6+ Fix from $2,3002020-12-11 MEDIUM 5.7 CVE-2020-27350 APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc… Advanced Package Tool 1.2.32ubuntu0.2 / 1.6.12ubuntu0.2+ Fix from $1,6002020-12-10 MEDIUM 5.5 CVE-2020-16587 A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.… Debian Linux Patch available Fix from $1,6002020-12-09 MEDIUM 5.5 CVE-2020-16588 A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of s… Debian Linux Patch available Fix from $1,6002020-12-09 MEDIUM 5.5 CVE-2020-16589 A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial o… Debian Linux Patch available Fix from $1,6002020-12-09 MEDIUM 6.0 CVE-2020-27821 A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds w… Debian Linux 5.2.0+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-25674 WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buf… Debian Linux 6.9.10-68 / 7.0.8-68+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-25676 In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in … Debian Linux 6.9.10-69 / 7.0.9-0+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-27750 A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a crafted file that is processed… Debian Linux 6.9.10-68 / 7.0.8-68+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-25665 The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 2… Debian Linux 6.9.10-68 / 7.0.8-68+ Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-28935 NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that wou… Debian Linux 1.13.0 / 4.3.4+ Fix from $1,6002020-12-07 CRITICAL 9.8 CVE-2020-29600 In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/… Debian Linux after 7.7 Fix from $2,3002020-12-07 HIGH 7.8 CVE-2020-29599EPSS 8% ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF… Debian Linux 6.9.11-40 / 7.0.10-40+ Fix from $1,9502020-12-07 HIGH 7.8 CVE-2020-27766 A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger unde… Debian Linux 6.9.10-69 / 7.0.8-69+ Fix from $1,9502020-12-04 MEDIUM 5.5 CVE-2020-27770 Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to … Debian Linux 6.9.10-68 / 7.0.8-68+ Fix from $1,6002020-12-04 MEDIUM 6.1 CVE-2020-29565 An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of v… Debian Linux 15.3.2 / 16.2.1+ Fix from $1,6002020-12-04 MEDIUM 5.5 CVE-2020-28916 hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address. Debian Linux Patch available Fix from $1,6002020-12-04