Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-25074EPSS 7% The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload … Debian Linux after 1.9.10 Fix from $2,3002020-11-10 HIGH 7.1 CVE-2017-18926 raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for t… Debian Linux Patch available Fix from $1,9502020-11-06 CRITICAL 9.8 CVE-2020-16846 KEVEPSS 100% An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel… Debian Linux 2015.8.10 / 2015.8.13+ Fix from $2,3002020-11-06 CRITICAL 9.8 CVE-2020-25592EPSS 58% In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH. Debian Linux 2015.8.10 / 2015.8.13+ Fix from $2,3002020-11-06 MEDIUM 6.5 CVE-2020-27617 eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data… Debian Linux Patch available Fix from $1,6002020-11-06 MEDIUM 5.5 CVE-2020-17490 The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions. Debian Linux 2015.8.10 / 2015.8.13+ Fix from $1,6002020-11-06 MEDIUM 6.5 CVE-2020-28241 libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c. Debian Linux 1.4.3+ Fix from $1,6002020-11-06 MEDIUM 6.3 CVE-2020-28049 An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged… Debian Linux 0.19.0+ Fix from $1,6002020-11-04 HIGH 7.5 CVE-2020-8037 The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. Debian Linux 10.14.6 / 10.15.7+ Fix from $1,9502020-11-04 HIGH 7.0 CVE-2020-15238 Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume… Debian Linux 2.1.4+ Fix from $1,9502020-10-27 HIGH 7.8 CVE-2020-27671 An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data le… Debian Linux after 4.14.0 Fix from $1,9502020-10-22 HIGH 7.5 CVE-2020-27638 receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code. Debian Linux 21.0+ Fix from $1,9502020-10-22 HIGH 8.6 CVE-2020-27153 In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a … Debian Linux 5.55+ Fix from $1,9502020-10-15 HIGH 7.8 CVE-2020-0423 In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in t… Debian Linux Mitigation only Fix from $1,9502020-10-14 MEDIUM 5.5 CVE-2020-15250 In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste… Debian Linux 3.1.1 / 4.13.1+ Fix from $1,6002020-10-12 MEDIUM 6.1 CVE-2020-26870 Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree… Debian Linux 2.0.17 / 21.1.0.00.01+ Fix from $1,6002020-10-07 CRITICAL 9.8 CVE-2020-11800EPSS 9% Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. Debian Linux 3.0.31+ Fix from $2,3002020-10-07 HIGH 7.5 CVE-2020-15598 Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are… Debian Linux after 3.0.4 Fix from $1,9502020-10-06 MEDIUM 5.5 CVE-2020-26571 The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init. Debian Linux after 0.20.0 Fix from $1,6002020-10-06 MEDIUM 5.7 CVE-2019-14558 Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Seri… Debian Linux Mitigation only Fix from $1,6002020-10-05 MEDIUM 5.5 CVE-2020-26519 Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service. Debian Linux 1.18.0+ Fix from $1,6002020-10-02 CRITICAL 9.8 CVE-2020-15227EPSS 34% Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters… Debian Linux 2.0.19 / 2.1.13+ Fix from $2,3002020-10-01 HIGH 8.1 CVE-2020-26117 In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificate… Debian Linux 1.11.0+ Fix from $1,9502020-09-27 MEDIUM 5.3 CVE-2020-25625 hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop. Debian Linux Patch available Fix from $1,6002020-09-25 MEDIUM 5.0 CVE-2020-25085 QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZ… Debian Linux Patch available Fix from $1,6002020-09-25 MEDIUM 5.5 CVE-2020-25601 An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event chan… Debian Linux after 4.14.0 Fix from $1,6002020-09-23 HIGH 8.1 CVE-2020-24750EPSS 7% FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcompon… Debian Linux 2.6.7.5 / 2.9.10.6+ Fix from $1,9502020-09-17 MEDIUM 5.5 CVE-2020-0427 In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no … Debian Linux Patch available Fix from $1,6002020-09-17 MEDIUM 6.5 CVE-2020-8927 A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression r… Debian Linux 1.0.8 / 7.0.9+ Fix from $1,6002020-09-15 CRITICAL 9.8 CVE-2020-24660 An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Host… Debian Linux after 2.0.8 Fix from $2,3002020-09-14