Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-20748 LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. Debian Linux 0.9.12 / 3.2.1.0+ Fix from $2,3002019-01-30 MEDIUM 6.5 CVE-2019-7149 A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cau… Debian Linux Patch available Fix from $1,6002019-01-29 MEDIUM 5.5 CVE-2019-7150 An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segm… Debian Linux Patch available Fix from $1,6002019-01-29 HIGH 8.1 CVE-2019-3462EPSS 15% Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM att… Advanced Package Tool 1.2.30+ Fix from $1,9502019-01-28 CRITICAL 9.8 CVE-2019-6978 The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is un… Debian Linux Patch available Fix from $2,3002019-01-28 MEDIUM 5.9 CVE-2019-6799EPSS 15% An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL… Debian Linux after 4.8.4 Fix from $1,6002019-01-26 HIGH 7.5 CVE-2018-20743 murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote att… Debian Linux after 1.2.19 Fix from $1,9502019-01-25 HIGH 7.1 CVE-2019-6956 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c. Debian Linux 2.9.0+ Fix from $1,9502019-01-25 MEDIUM 5.3 CVE-2017-3138EPSS 6% named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel… Debian Linux Mitigation only Fix from $1,6002019-01-16 CRITICAL 9.8 CVE-2018-20721 URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address c… Debian Linux 0.9.1+ Fix from $2,3002019-01-16 MEDIUM 5.2 CVE-2019-3811 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the… Debian Linux 2.1+ Fix from $1,6002019-01-15 CRITICAL 9.8 CVE-2019-6256 A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer cr… Debian Linux No fix yet Fix from $2,3002019-01-14 HIGH 8.8 CVE-2019-6250EPSS 9% A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::… Debian Linux 4.3.1+ Fix from $1,9502019-01-13 HIGH 8.8 CVE-2019-6245 An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned … Debian Linux Patch available Fix from $1,9502019-01-13 HIGH 7.8 CVE-2018-4180 In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions. Debian Linux 10.13.5+ Fix from $1,9502019-01-11 MEDIUM 6.7 CVE-2019-6133 In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization deci… Debian Linux Patch available Fix from $1,6002019-01-11 MEDIUM 5.3 CVE-2018-20685 In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. … Debian Linux after 7.9 Fix from $1,6002019-01-10 MEDIUM 6.5 CVE-2018-20662 In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of… Debian Linux Patch available Fix from $1,6002019-01-03 MEDIUM 5.5 CVE-2018-19478 In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file. Debian Linux 9.26+ Fix from $1,6002019-01-02 CRITICAL 10.0 CVE-2018-14721EPSS 10% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure … Debian Linux 2.6.7.2 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14718EPSS 13% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class… Debian Linux 2.6.7.3 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14719EPSS 10% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt an… Debian Linux 2.6.7.3 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14720EPSS 8% FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci… Debian Linux 2.6.7.2 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19360EPSS 11% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms c… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19361EPSS 11% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from po… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19362EPSS 11% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core cla… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02 HIGH 7.8 CVE-2019-3500 aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to … Debian Linux Patch available Fix from $1,9502019-01-02 MEDIUM 6.5 CVE-2018-20622 JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. Debian Linux Mitigation only Fix from $1,6002018-12-31 MEDIUM 6.5 CVE-2018-20584 JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format. Debian Linux Patch available Fix from $1,6002018-12-30 MEDIUM 6.5 CVE-2018-20570 jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read. Debian Linux No fix yet Fix from $1,6002018-12-28