Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-5808 An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-based bu… Debian Linux 0.18.9+ Fix from $1,9502018-12-07 CRITICAL 9.1 CVE-2018-19857 The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies… Debian Linux No fix yet Fix from $2,3002018-12-05 HIGH 8.8 CVE-2018-19788EPSS 11% A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command. Debian Linux Patch available Fix from $1,9502018-12-03 MEDIUM 6.1 CVE-2018-19787 An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, al… Debian Linux 4.2.5+ Fix from $1,6002018-12-02 MEDIUM 5.5 CVE-2018-19777 In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool. Debian Linux No fix yet Fix from $1,6002018-11-30 MEDIUM 6.5 CVE-2018-19758 There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service. Debian Linux No fix yet Fix from $1,6002018-11-30 MEDIUM 6.5 CVE-2018-19497 In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows atta… Debian Linux after 4.6.4 Fix from $1,6002018-11-29 HIGH 8.1 CVE-2018-19662 An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of servic… Debian Linux Patch available Fix from $1,9502018-11-29 MEDIUM 6.5 CVE-2018-19661 An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of servic… Debian Linux No fix yet Fix from $1,6002018-11-29 HIGH 8.8 CVE-2018-19540 An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.1… Debian Linux No fix yet Fix from $1,9502018-11-26 MEDIUM 6.5 CVE-2018-19539 An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a… Debian Linux No fix yet Fix from $1,6002018-11-26 MEDIUM 6.5 CVE-2018-19535 In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-base… Debian Linux after 0.26 Fix from $1,6002018-11-26 HIGH 7.8 CVE-2018-19490 An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amoun… Debian Linux Patch available Fix from $1,9502018-11-23 HIGH 7.8 CVE-2018-19491 An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in … Debian Linux Patch available Fix from $1,9502018-11-23 HIGH 7.8 CVE-2018-19492 An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in… Debian Linux Patch available Fix from $1,9502018-11-23 HIGH 7.8 CVE-2018-19475EPSS 10% psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not… Debian Linux Patch available Fix from $1,9502018-11-23 HIGH 7.8 CVE-2018-19476 psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusio… Debian Linux Patch available Fix from $1,9502018-11-23 HIGH 7.8 CVE-2018-19477 psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusi… Debian Linux Patch available Fix from $1,9502018-11-23 MEDIUM 6.5 CVE-2018-19432 An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a den… Debian Linux Patch available Fix from $1,6002018-11-22 CRITICAL 9.8 CVE-2018-19409EPSS 8% An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used. Debian Linux 9.26+ Fix from $2,3002018-11-21 HIGH 7.2 CVE-2018-19274EPSS 5% Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deseria… Debian Linux 3.2.4+ Fix from $1,9502018-11-17 HIGH 8.8 CVE-2018-19296 PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. Debian Linux 5.2.27 / 6.0.6+ Fix from $1,9502018-11-16 MEDIUM 6.1 CVE-2018-16471 There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method… Debian Linux 1.6.11 / 2.0.6+ Fix from $1,6002018-11-13 HIGH 7.8 CVE-2018-19216 Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c. Debian Linux 2.13.02+ Fix from $1,9502018-11-12 MEDIUM 6.5 CVE-2018-19210 In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service a… Debian Linux No fix yet Fix from $1,6002018-11-12 MEDIUM 6.1 CVE-2018-19206EPSS 60% steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, with… Debian Linux 1.3.8+ Fix from $1,6002018-11-12 CRITICAL 9.8 CVE-2018-19198 An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function bec… Debian Linux 0.9.0+ Fix from $2,3002018-11-12 CRITICAL 9.8 CVE-2018-19199 An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function becaus… Debian Linux 0.9.0+ Fix from $2,3002018-11-12 HIGH 7.5 CVE-2018-19200 An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function. Debian Linux 0.9.0 / 8.0+ Fix from $1,9502018-11-12 MEDIUM 6.5 CVE-2018-19143 Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via … Debian Linux 4.0.33 / 5.0.31+ Fix from $1,6002018-11-11