Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-12268 jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow. Debian Linux 0.18+ Fix from $2,3002020-04-27 MEDIUM 6.1 CVE-2020-12137 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks a… Debian Linux 2.1.30+ Fix from $1,6002020-04-24 CRITICAL 9.8 CVE-2020-11945EPSS 27% An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that ar… Debian Linux 4.11 / 5.0.2+ Fix from $2,3002020-04-23 CRITICAL 9.8 CVE-2019-12519EPSS 7% An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function … Debian Linux after 5.0.1 Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2019-12524 An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid… Debian Linux after 4.7 Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2020-11729 An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity… Debian Linux after 0.60 Fix from $2,3002020-04-15 HIGH 7.5 CVE-2020-11728 An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session ke… Debian Linux after 0.60 Fix from $1,9502020-04-15 MEDIUM 5.5 CVE-2020-11740 An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about o… Debian Linux after 4.13.0 Fix from $1,6002020-04-14 HIGH 7.5 CVE-2020-11724 An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.ca… Debian Linux 1.15.8.4+ Fix from $1,9502020-04-12 HIGH 7.5 CVE-2020-11653 An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a … Debian Linux 6.0.6 / 6.2.3+ Fix from $1,9502020-04-08 HIGH 8.1 CVE-2020-11619 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.ao… Debian Linux 2.9.10.4+ Fix from $1,9502020-04-07 HIGH 8.1 CVE-2020-11620EPSS 6% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jel… Debian Linux 2.9.10.4+ Fix from $1,9502020-04-07 HIGH 7.5 CVE-2020-11612EPSS 9% The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send … Debian Linux 4.1.46+ Fix from $1,9502020-04-07 HIGH 7.8 CVE-2019-14868 In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypas… Debian Linux 10.15.5+ Fix from $1,9502020-04-02 HIGH 8.8 CVE-2020-11100EPSS 61% In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a… Debian Linux 2.1.4+ Fix from $1,9502020-04-02 HIGH 7.8 CVE-2020-5291 Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2`… Debian Linux 0.4.1+ Fix from $1,9502020-03-31 CRITICAL 9.8 CVE-2020-10595 pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library… Debian Linux 4.9+ Fix from $2,3002020-03-31 HIGH 8.8 CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* … Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-11113EPSS 6% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 7.5 CVE-2020-1772 It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users… Debian Linux after 7.0.15 Fix from $1,9502020-03-27 HIGH 8.8 CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPan… Debian Linux 2.7.9.7 / 2.8.11.6+ Fix from $1,9502020-03-26 HIGH 8.8 CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.pro… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-26 CRITICAL 9.8 CVE-2020-6072 An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels … Debian Linux No fix yet Fix from $2,3002020-03-24 HIGH 7.5 CVE-2020-6071 An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compr… Debian Linux No fix yet Fix from $1,9502020-03-24 HIGH 7.5 CVE-2020-6073 An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA … Debian Linux No fix yet Fix from $1,9502020-03-24 HIGH 7.5 CVE-2020-6077 An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages… Debian Linux No fix yet Fix from $1,9502020-03-24 HIGH 7.5 CVE-2020-6078 An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages… Debian Linux No fix yet Fix from $1,9502020-03-24 HIGH 7.5 CVE-2020-6079 An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors wh… Debian Linux No fix yet Fix from $1,9502020-03-24 HIGH 7.5 CVE-2020-6080 An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors wh… Debian Linux No fix yet Fix from $1,9502020-03-24