Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-14468
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
Debian Linux
after 15.0.1
CRITICAL 9.8
CVE-2019-16942EPSS 6%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …
Debian Linux
2.6.7.3 / 2.8.11.5+
CRITICAL 9.8
CVE-2019-16943
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …
Debian Linux
2.6.7.3 / 2.8.11.5+
HIGH 8.8
CVE-2019-16993
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa…
Debian Linux
after 3.1.7
HIGH 7.5
CVE-2019-16869EPSS 8%
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP …
Debian Linux
4.1.42+
MEDIUM 6.1
CVE-2017-18635
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the …
Debian Linux
0.6.2+
CRITICAL 9.8
CVE-2019-15941
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat…
Debian Linux
after 2.0.5
HIGH 7.5
CVE-2019-5094
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause …
Debian Linux
after 1.45.3
HIGH 7.8
CVE-2019-16729
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation …
Debian Linux
1.0.7-1+
MEDIUM 6.1
CVE-2019-16728
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
Debian Linux
2.0.1+
MEDIUM 6.5
CVE-2019-16710
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
Debian Linux
Patch available
MEDIUM 6.5
CVE-2019-16711
ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
Debian Linux
Patch available
MEDIUM 5.3
CVE-2019-16394EPSS 8%
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exis…
Debian Linux
3.1.11 / 3.2.5+
CRITICAL 9.8
CVE-2019-16378
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect …
Debian Linux
after 1.3.2
MEDIUM 6.5
CVE-2018-21015
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and applicat…
Debian Linux
No fix yet
MEDIUM 6.5
CVE-2018-21016
audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-re…
Debian Linux
No fix yet
MEDIUM 6.5
CVE-2019-16275
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address valida…
Debian Linux
after 2.9
HIGH 7.5
CVE-2016-10937
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
Debian Linux
after 2.6.12
CRITICAL 9.8
CVE-2019-15846EPSS 36%
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
Debian Linux
4.92.2+
MEDIUM 6.4
CVE-2019-15946
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
Debian Linux
after 0.19.0
MEDIUM 6.4
CVE-2019-15945
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
Debian Linux
after 0.19.0
MEDIUM 5.9
CVE-2019-15939
An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modules/objdetect/src/hog.cpp.
Debian Linux
after 4.1.0
HIGH 8.8
CVE-2018-21010
OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
Debian Linux
2.3.1+
HIGH 7.5
CVE-2019-15892EPSS 6%
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to tr…
Debian Linux
6.0.4 / 6.2.1+
HIGH 8.8
CVE-2015-9381
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
Debian Linux
2.6.1+
MEDIUM 6.5
CVE-2015-9382
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face…
Debian Linux
2.6.1+
MEDIUM 6.5
CVE-2015-9383
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
Debian Linux
2.6.2+
HIGH 7.8
CVE-2019-14533
The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
Debian Linux
Patch available
HIGH 7.8
CVE-2019-14776
A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.
Debian Linux
Patch available
HIGH 7.8
CVE-2019-14777
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
Debian Linux
Patch available