Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-10938EPSS 5% GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c. Debian Linux 1.3.35+ Fix from $2,3002020-03-24 MEDIUM 5.3 CVE-2020-9359 KDE Okular before 1.10.0 allows code execution via an action link in a PDF document. Debian Linux 1.10.0 / 19.12.3+ Fix from $1,6002020-03-24 MEDIUM 6.5 CVE-2020-8866EPSS 10% This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticat… Debian Linux 2.0.20+ Fix from $1,6002020-03-23 MEDIUM 6.3 CVE-2020-8865EPSS 7% This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentica… Debian Linux Mitigation only Fix from $1,6002020-03-23 CRITICAL 9.8 CVE-2020-9760 An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buff… Debian Linux 2.7.1+ Fix from $2,3002020-03-23 HIGH 8.0 CVE-2020-10802 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly esca… Debian Linux 4.9.5 / 5.0.2+ Fix from $1,9502020-03-22 MEDIUM 5.4 CVE-2020-10803 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS… Debian Linux 4.9.5 / 5.0.2+ Fix from $1,6002020-03-22 MEDIUM 6.1 CVE-2019-18860EPSS 6% Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. Debian Linux 4.9+ Fix from $1,6002020-03-20 HIGH 8.8 CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.trans… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-18 HIGH 8.8 CVE-2020-10673EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.type… Debian Linux 2.6.7.4 / 2.9.10.4+ Fix from $1,9502020-03-18 MEDIUM 6.5 CVE-2019-12921EPSS 8% In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of Translate… Debian Linux 1.3.32+ Fix from $1,6002020-03-18 HIGH 7.8 CVE-2019-20326 A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.… Debian Linux 2.4.5 / 3.8.3+ Fix from $1,9502020-03-16 HIGH 7.5 CVE-2020-0034 In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information … Debian Linux Mitigation only Fix from $1,9502020-03-10 HIGH 7.7 CVE-2020-5258 In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to in… Debian Linux 1.11.10 / 1.12.8+ Fix from $1,9502020-03-10 MEDIUM 5.5 CVE-2012-1096 NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when ad… Debian Linux after 0.9.0 Fix from $1,6002020-03-10 CRITICAL 9.8 CVE-2020-10232 In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaf… Debian Linux after 4.8.0 Fix from $2,3002020-03-09 MEDIUM 6.5 CVE-2019-20503 usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. Debian Linux 0.9.4.0+ Fix from $1,6002020-03-06 HIGH 7.8 CVE-2020-9549 In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document. Debian Linux after 0.19 Fix from $1,9502020-03-02 HIGH 7.5 CVE-2019-10064 hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, w… Debian Linux 2.6+ Fix from $1,9502020-02-28 HIGH 7.5 CVE-2020-9274EPSS 6% An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup… Debian Linux 1.0.50+ Fix from $1,9502020-02-26 HIGH 7.5 CVE-2015-9542 add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based b… Debian Linux Patch available Fix from $1,9502020-02-24 CRITICAL 9.8 CVE-2020-9355 danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled. Debian Linux 1.2.11+ Fix from $2,3002020-02-23 HIGH 7.8 CVE-2012-1093 The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during pac… X11 Common 1+ Fix from $1,9502020-02-21 MEDIUM 5.5 CVE-2012-0844 Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar. Debian Linux after 2.8 Fix from $1,6002020-02-21 HIGH 8.8 CVE-2020-9273EPSS 12% In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool i… Debian Linux 3.0+ Fix from $1,9502020-02-20 MEDIUM 6.1 CVE-2019-20479 A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. Debian Linux 2.4.1+ Fix from $1,6002020-02-20 HIGH 7.5 CVE-2020-6062EPSS 6% An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST reques… Debian Linux No fix yet Fix from $1,9502020-02-19 HIGH 8.8 CVE-2015-0258 Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticate… Debian Linux 2.1+ Fix from $1,9502020-02-17 MEDIUM 6.1 CVE-2019-10785 dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xm… Debian Linux 1.11.9 / 1.12.7+ Fix from $1,6002020-02-13 HIGH 7.0 CVE-2019-19921 runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an… Debian Linux after 0.1.1 Fix from $1,9502020-02-12