Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-15566 An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel … Debian Linux after 4.13.1 Fix from $1,6002020-07-07 MEDIUM 6.5 CVE-2020-15563 An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests… Debian Linux after 4.13.1 Fix from $1,6002020-07-07 MEDIUM 5.5 CVE-2020-15569 PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor. Debian Linux after 1.02.00 Fix from $1,6002020-07-06 MEDIUM 6.1 CVE-2020-15562 An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail mess… Debian Linux 1.2.11 / 1.3.14+ Fix from $1,6002020-07-06 HIGH 8.6 CVE-2020-8161 A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory a… Debian Linux 2.2.0+ Fix from $1,9502020-07-02 CRITICAL 9.1 CVE-2020-15472 In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated … Debian Linux after 3.2 Fix from $2,3002020-07-01 HIGH 7.5 CVE-2020-15476 In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c. Debian Linux after 3.2 Fix from $1,9502020-07-01 MEDIUM 6.5 CVE-2020-15389 jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory… Debian Linux after 2.3.1 Fix from $1,6002020-06-29 HIGH 7.5 CVE-2020-4067 In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information bet… Debian Linux 4.5.1.3+ Fix from $1,9502020-06-29 MEDIUM 5.9 CVE-2020-14954 Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS"… Debian Linux 1.14.4 / 20200619+ Fix from $1,6002020-06-21 HIGH 7.5 CVE-2020-8184 A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an… Debian Linux 2.1.4 / 2.2.3+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-14401 An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow. Debian Linux 0.9.13 / 3.2.1.0+ Fix from $1,6002020-06-17 HIGH 7.5 CVE-2020-14399 An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: ther… Debian Linux 0.9.13+ Fix from $1,9502020-06-17 HIGH 7.5 CVE-2020-14400 An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Thi… Debian Linux 0.9.13+ Fix from $1,9502020-06-17 MEDIUM 5.4 CVE-2020-4051 In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8,… Debian Linux 1.11.11 / 1.12.9+ Fix from $1,6002020-06-15 HIGH 7.5 CVE-2020-14148 The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. Debian Linux after 25.0 Fix from $1,9502020-06-15 HIGH 7.1 CVE-2020-14152 In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing exces… Debian Linux 9d+ Fix from $1,9502020-06-15 MEDIUM 6.5 CVE-2020-0182 In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d… Debian Linux Patch available Fix from $1,6002020-06-11 MEDIUM 6.1 CVE-2020-13965 KEVEPSS 77% An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am… Debian Linux 1.3.12 / 1.4.5+ Fix from $1,6002020-06-09 HIGH 7.8 CVE-2020-13428 A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS… Debian Linux 3.0.11+ Fix from $1,9502020-06-08 HIGH 7.5 CVE-2020-13881 In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. Debian Linux 2020.1.2+ Fix from $1,9502020-06-06 HIGH 7.5 CVE-2020-13848 Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a N… Debian Linux after 1.12.1 Fix from $1,9502020-06-04 HIGH 7.5 CVE-2020-11080EPSS 5% In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a mal… Debian Linux 1.41.0 / 10.21.0+ Fix from $1,9502020-06-03 MEDIUM 5.5 CVE-2020-11089 In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_wr… Debian Linux 2.1.0+ Fix from $1,6002020-05-29 MEDIUM 5.4 CVE-2020-11086 In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to… Debian Linux 2.1.0+ Fix from $1,6002020-05-29 MEDIUM 5.4 CVE-2020-11087 In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0. Debian Linux 2.1.0+ Fix from $1,6002020-05-29 MEDIUM 5.4 CVE-2020-11088 In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0. Debian Linux 2.1.0+ Fix from $1,6002020-05-29 MEDIUM 6.8 CVE-2020-11039 In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and writte… Debian Linux 2.1.0+ Fix from $1,6002020-05-29 MEDIUM 6.5 CVE-2020-11019 In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an… Debian Linux 2.1.0+ Fix from $1,6002020-05-29 MEDIUM 5.4 CVE-2020-11038 In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instru… Debian Linux 2.1.0+ Fix from $1,6002020-05-29