Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2014-6262EPSS 7% Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attacker… Debian Linux 4.2.5+ Fix from $1,9502020-02-12 HIGH 8.1 CVE-2020-5529 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can … Debian Linux 2.37.0+ Fix from $1,9502020-02-11 CRITICAL 9.8 CVE-2020-8840EPSS 27% FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC… Debian Linux 2.7.9.7 / 2.8.11.5+ Fix from $2,3002020-02-10 MEDIUM 5.6 CVE-2020-8608 In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code. Debian Linux Patch available Fix from $1,6002020-02-06 HIGH 8.8 CVE-2020-5208 It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lea… Debian Linux Patch available Fix from $1,9502020-02-05 HIGH 7.5 CVE-2020-8449EPSS 8% An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access … Debian Linux 4.10+ Fix from $1,9502020-02-04 CRITICAL 9.8 CVE-2020-8597EPSS 20% eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. Debian Linux 03.04.10+ Fix from $2,3002020-02-03 CRITICAL 9.1 CVE-2019-20444EPSS 9% HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incor… Debian Linux 4.1.44+ Fix from $2,3002020-01-29 CRITICAL 9.1 CVE-2019-20445EPSS 13% HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-En… Debian Linux 4.1.44+ Fix from $2,3002020-01-29 HIGH 7.8 CVE-2019-18634EPSS 19% In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwf… Debian Linux 1.8.26+ Fix from $1,9502020-01-29 CRITICAL 9.8 CVE-2020-7247 KEVEPSS 99% smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as… Debian Linux Patch available Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2015-8011EPSS 5% Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (da… Debian Linux 0.8.0+ Fix from $2,3002020-01-28 HIGH 8.8 CVE-2020-8112 opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different… Debian Linux No fix yet Fix from $1,9502020-01-28 CRITICAL 9.8 CVE-2020-8086 The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f… Debian Linux after 2020-01-27 Fix from $2,3002020-01-28 MEDIUM 5.5 CVE-2020-0549 Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure… Debian Linux Mitigation only Fix from $1,6002020-01-28 HIGH 7.5 CVE-2015-0294 GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate. Debian Linux 3.3.13+ Fix from $1,9502020-01-27 MEDIUM 5.5 CVE-2020-8003 A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture al… Debian Linux after 0.8.1 Fix from $1,6002020-01-27 MEDIUM 5.5 CVE-2020-8002 A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via commands that attempt… Debian Linux after 0.8.1 Fix from $1,6002020-01-27 CRITICAL 9.8 CVE-2014-4172EPSS 6% A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.… Debian Linux 1.0.2 / 1.3.3+ Fix from $2,3002020-01-24 HIGH 7.5 CVE-2019-16792 Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Lengt… Debian Linux after 1.3.1 Fix from $1,9502020-01-22 HIGH 7.5 CVE-2019-20387 repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of … Debian Linux 0.7.6+ Fix from $1,9502020-01-21 HIGH 7.5 CVE-2019-20388 xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. Debian Linux Patch available Fix from $1,9502020-01-21 HIGH 8.1 CVE-2020-7040 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege … Debian Linux after 3.5 Fix from $1,9502020-01-21 MEDIUM 5.5 CVE-2020-5202 apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool… Debian Linux after 3.3 Fix from $1,6002020-01-21 CRITICAL 9.8 CVE-2019-17361EPSS 15% In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticat… Debian Linux after 2019.2.0 Fix from $2,3002020-01-17 MEDIUM 5.6 CVE-2020-7039 tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a h… Debian Linux Patch available Fix from $1,6002020-01-16 MEDIUM 6.1 CVE-2020-7106 Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and us… Debian Linux 1.2.9+ Fix from $1,6002020-01-16 HIGH 7.5 CVE-2015-5230EPSS 9% The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of se… Debian Linux 3.4.6+ Fix from $1,9502020-01-15 HIGH 7.5 CVE-2019-19728 SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. Debian Linux 18.08.9 / 19.05.5+ Fix from $1,9502020-01-13 MEDIUM 6.1 CVE-2020-1766 Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious java… Debian Linux after 7.0.13 Fix from $1,6002020-01-10