Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-12086EPSS 22% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a sp… Debian Linux 2.6.7.3 / 2.7.9.6+ Fix from $1,9502019-05-17 HIGH 7.8 CVE-2019-3839 It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted P… Debian Linux 9.27+ Fix from $1,9502019-05-16 HIGH 7.5 CVE-2019-12111 A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c. Debian Linux after 2.1 Fix from $1,9502019-05-15 CRITICAL 9.8 CVE-2019-11766 dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature. Debian Linux 6.11.7 / 7.2.2+ Fix from $2,3002019-05-05 CRITICAL 9.8 CVE-2019-11627 gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID. Debian Linux 2.10+ Fix from $2,3002019-04-30 HIGH 7.8 CVE-2019-5429 Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directo… Debian Linux 3.41.0+ Fix from $1,9502019-04-29 MEDIUM 5.3 CVE-2019-11579 dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED. Debian Linux 7.2.1+ Fix from $1,6002019-04-28 HIGH 8.8 CVE-2019-11506 In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/m… Debian Linux Patch available Fix from $1,9502019-04-24 HIGH 8.8 CVE-2019-11505 In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c… Debian Linux after 1.3.31 Fix from $1,9502019-04-24 HIGH 8.8 CVE-2019-9928EPSS 6% GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing rem… Debian Linux 1.16.0+ Fix from $1,9502019-04-24 MEDIUM 6.1 CVE-2019-10241EPSS 10% In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES… Debian Linux after 11.7.0 Fix from $1,6002019-04-22 MEDIUM 5.3 CVE-2019-10247EPSS 6% In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combinati… Debian Linux after 3.1.3 Fix from $1,6002019-04-22 HIGH 8.1 CVE-2019-11455 A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of a… Debian Linux 5.25.3+ Fix from $1,9502019-04-22 MEDIUM 5.9 CVE-2019-3902 A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil… Debian Linux 4.9+ Fix from $1,6002019-04-22 HIGH 8.8 CVE-2019-11338 libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of servi… Debian Linux Patch available Fix from $1,9502019-04-19 HIGH 7.5 CVE-2019-3883EPSS 8% In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout'… Debian Linux after 1.4.1.2 Fix from $1,9502019-04-17 HIGH 7.8 CVE-2019-11221 GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. Debian Linux No fix yet Fix from $1,9502019-04-15 HIGH 7.8 CVE-2019-11222 gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file. Debian Linux Patch available Fix from $1,9502019-04-15 HIGH 8.8 CVE-2019-11071 SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishand… Debian Linux 3.1.10 / 3.2.4+ Fix from $1,9502019-04-10 MEDIUM 5.4 CVE-2019-3880 A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this fla… Debian Linux 4.8.11 / 4.9.6+ Fix from $1,6002019-04-09 MEDIUM 5.4 CVE-2019-11025 In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options)… Debian Linux 1.2.3+ Fix from $1,6002019-04-08 MEDIUM 5.5 CVE-2019-1788 A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior c… Debian Linux after 0.101.1 Fix from $1,6002019-04-08 CRITICAL 9.1 CVE-2019-11006 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attac… Debian Linux after 1.3.31 Fix from $2,3002019-04-08 HIGH 8.8 CVE-2019-11008 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote … Debian Linux after 1.3.31 Fix from $1,9502019-04-08 HIGH 8.1 CVE-2019-11007 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attacke… Debian Linux after 1.3.31 Fix from $1,9502019-04-08 HIGH 8.1 CVE-2019-11009 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attacke… Debian Linux after 1.3.31 Fix from $1,9502019-04-08 MEDIUM 6.5 CVE-2019-11010 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a de… Debian Linux after 1.3.31 Fix from $1,6002019-04-08 MEDIUM 5.5 CVE-2019-1787 A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could all… Debian Linux after 0.101.1 Fix from $1,6002019-04-08 MEDIUM 6.1 CVE-2019-10904 Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. Debian Linux No fix yet Fix from $1,6002019-04-06 MEDIUM 6.5 CVE-2019-10868 In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authe… Debian Linux 4.2.21 / 4.4.19+ Fix from $1,6002019-04-05