Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-7175 In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c. Debian Linux 6.9.10-25 / 7.0.8-25+ Fix from $1,9502019-03-07 HIGH 7.8 CVE-2019-1999 In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privileg… Debian Linux No fix yet Fix from $1,9502019-02-28 CRITICAL 9.8 CVE-2019-9215 In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function. Debian Linux 2019.02.27+ Fix from $2,3002019-02-28 HIGH 7.8 CVE-2019-9210 In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted m… Debian Linux No fix yet Fix from $1,9502019-02-27 HIGH 8.8 CVE-2019-9200 A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending… Debian Linux No fix yet Fix from $1,9502019-02-26 HIGH 7.5 CVE-2018-5817 A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited … Debian Linux 0.19.1+ Fix from $1,9502019-02-20 HIGH 7.5 CVE-2018-5818 An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infin… Debian Linux 0.19.1+ Fix from $1,9502019-02-20 HIGH 7.5 CVE-2018-5819 An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust availa… Debian Linux 0.19.1+ Fix from $1,9502019-02-20 CRITICAL 9.8 CVE-2019-7164 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. Debian Linux after 1.2.17 Fix from $2,3002019-02-20 HIGH 8.8 CVE-2019-8907 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or… Debian Linux No fix yet Fix from $1,9502019-02-18 MEDIUM 6.1 CVE-2016-10742 Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the req… Debian Linux after 3.4.3 Fix from $1,6002019-02-17 HIGH 7.8 CVE-2019-8379 An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can … Debian Linux 2.1+ Fix from $1,9502019-02-17 HIGH 7.8 CVE-2019-8383 An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be trigg… Debian Linux after 2.1 Fix from $1,9502019-02-17 MEDIUM 5.0 CVE-2019-8354 An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When t… Debian Linux Mitigation only Fix from $1,6002019-02-15 HIGH 8.2 CVE-2019-8308 Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side… Debian Linux 1.0.7+ Fix from $1,9502019-02-12 MEDIUM 6.5 CVE-2018-15587 GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a va… Debian Linux after 3.28.2 Fix from $1,6002019-02-11 MEDIUM 6.5 CVE-2019-7663 An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpS… Debian Linux Patch available Fix from $1,6002019-02-09 MEDIUM 5.5 CVE-2019-7665 In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can… Debian Linux No fix yet Fix from $1,6002019-02-09 HIGH 8.1 CVE-2019-7659 Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impa… Debian Linux 2.8.75+ Fix from $1,9502019-02-09 CRITICAL 9.8 CVE-2019-7653 The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowi… Debian Linux No fix yet Fix from $2,3002019-02-09 HIGH 8.8 CVE-2019-7637 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-08 HIGH 8.8 CVE-2019-7638 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-08 HIGH 8.1 CVE-2019-7635 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-08 HIGH 8.1 CVE-2019-7636 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-08 HIGH 8.1 CVE-2019-7578 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-07 HIGH 8.8 CVE-2019-7572 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-07 HIGH 8.8 CVE-2019-7573 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the… Debian Linux after 2.0.9 Fix from $1,9502019-02-07 HIGH 8.8 CVE-2019-7574 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-07 HIGH 8.8 CVE-2019-7575 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c. Debian Linux after 2.0.9 Fix from $1,9502019-02-07 HIGH 8.8 CVE-2019-7576 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside th… Debian Linux after 2.0.9 Fix from $1,9502019-02-07