Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2018-19132EPSS 6% Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet. Debian Linux 4.4+ Fix from $1,6002018-11-09 CRITICAL 9.8 CVE-2018-19115 keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, becaus… Debian Linux 2.0.7+ Fix from $2,3002018-11-08 MEDIUM 6.5 CVE-2018-19107 In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-bas… Debian Linux Patch available Fix from $1,6002018-11-08 MEDIUM 6.5 CVE-2018-19108 In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an… Debian Linux Patch available Fix from $1,6002018-11-08 HIGH 7.5 CVE-2018-19052EPSS 14% An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single dir… Debian Linux 1.4.50+ Fix from $1,9502018-11-07 HIGH 7.5 CVE-2018-16472 A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inhe… Debian Linux after 1.0.1 Fix from $1,9502018-11-06 HIGH 7.8 CVE-2018-9516 In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local … Debian Linux Patch available Fix from $1,9502018-11-06 HIGH 7.8 CVE-2018-9422 In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional p… Debian Linux Patch available Fix from $1,9502018-11-06 HIGH 8.1 CVE-2018-18820EPSS 49% A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP cl… Debian Linux 2.4.4+ Fix from $1,9502018-11-05 MEDIUM 6.5 CVE-2018-18897 An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo. Debian Linux No fix yet Fix from $1,6002018-11-02 MEDIUM 6.5 CVE-2016-2120 An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server b… Debian Linux after 4.0.1 Fix from $1,6002018-11-01 HIGH 8.8 CVE-2018-14651 It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authentica… Debian Linux after 4.1.4 Fix from $1,9502018-10-31 MEDIUM 6.5 CVE-2018-14661 It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vuln… Debian Linux Mitigation only Fix from $1,6002018-10-31 HIGH 7.8 CVE-2018-18718 An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c becaus… Debian Linux after 3.6.2 Fix from $1,9502018-10-29 HIGH 8.8 CVE-2018-15688 A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected… Debian Linux Patch available Fix from $1,9502018-10-26 HIGH 7.8 CVE-2018-18654 Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in … Crossroads Mitigation only Fix from $1,9502018-10-26 MEDIUM 5.5 CVE-2018-18605 A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka … Debian Linux No fix yet Fix from $1,6002018-10-23 MEDIUM 5.5 CVE-2018-18606 An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binu… Debian Linux No fix yet Fix from $1,6002018-10-23 MEDIUM 5.5 CVE-2018-18607 An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2… Debian Linux No fix yet Fix from $1,6002018-10-23 MEDIUM 6.5 CVE-2018-18584 In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum bloc… Debian Linux 1.8+ Fix from $1,6002018-10-23 HIGH 8.8 CVE-2018-18557EPSS 15% LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.… Debian Linux No fix yet Fix from $1,9502018-10-22 HIGH 7.5 CVE-2018-18541 In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker… Debian Linux 0.6.5+ Fix from $1,9502018-10-20 HIGH 8.6 CVE-2018-18284EPSS 16% Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator. Debian Linux Patch available Fix from $1,9502018-10-19 MEDIUM 6.5 CVE-2018-18520 An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar… Debian Linux after 0.174 Fix from $1,6002018-10-19 MEDIUM 5.5 CVE-2018-18521 Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (… Debian Linux Patch available Fix from $1,6002018-10-19 CRITICAL 9.8 CVE-2018-4013EPSS 10% An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specia… Debian Linux No fix yet Fix from $2,3002018-10-19 CRITICAL 9.8 CVE-2018-5188 Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presum… Debian Linux 52.9 / 60.1.0+ Fix from $2,3002018-10-18 CRITICAL 9.8 CVE-2018-5187 Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough … Debian Linux 60.0 / 60.1.0+ Fix from $2,3002018-10-18 MEDIUM 5.5 CVE-2018-15378 A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to… Debian Linux 0.100.2+ Fix from $1,6002018-10-15 MEDIUM 6.3 CVE-2018-18073 Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack… Debian Linux Patch available Fix from $1,6002018-10-15