Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2018-15572 The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context swi… Debian Linux 4.18.1+ Fix from $1,6002018-08-20 CRITICAL 9.8 CVE-2018-15494 In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. Debian Linux 1.14+ Fix from $2,3002018-08-18 HIGH 7.5 CVE-2018-15501 In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packe… Debian Linux 0.26.6 / 0.27.4+ Fix from $1,9502018-08-18 MEDIUM 5.3 CVE-2018-15473EPSS 99% OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packe… Debian Linux after 7.7 Fix from $1,6002018-08-17 MEDIUM 6.5 CVE-2018-15469 An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an… Debian Linux after 4.11.0 Fix from $1,6002018-08-17 HIGH 8.8 CVE-2018-10873 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check… Debian Linux Patch available Fix from $1,9502018-08-17 HIGH 8.1 CVE-2018-14348 libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information. Debian Linux after 0.41 Fix from $1,9502018-08-14 HIGH 8.8 CVE-2018-15209 ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and … Debian Linux No fix yet Fix from $1,9502018-08-08 HIGH 8.8 CVE-2018-14593 An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is … Debian Linux after 6.0.9 Fix from $1,9502018-08-04 HIGH 7.5 CVE-2018-14912EPSS 93% cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cg… Debian Linux 1.2.1+ Fix from $1,9502018-08-03 CRITICAL 9.8 CVE-2015-9262EPSS 6% _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a… Debian Linux 1.1.15+ Fix from $2,3002018-08-01 HIGH 7.8 CVE-2016-8654 A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before… Debian Linux 2.0.0+ Fix from $1,9502018-08-01 MEDIUM 6.5 CVE-2016-9572 A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for de… Debian Linux Patch available Fix from $1,6002018-08-01 MEDIUM 5.3 CVE-2018-14432 In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may by… Debian Linux 11.0.4+ Fix from $1,6002018-07-31 HIGH 7.4 CVE-2018-8019 When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for r… Debian Linux after 1.2.16 Fix from $1,9502018-07-31 HIGH 7.4 CVE-2018-8020 Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multi… Debian Linux after 1.2.16 Fix from $1,9502018-07-31 CRITICAL 9.8 CVE-2018-14767EPSS 29% In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an… Debian Linux 5.0.7 / 5.1.4+ Fix from $2,3002018-07-31 MEDIUM 5.5 CVE-2018-10883 A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of s… Debian Linux 4.9.110+ Fix from $1,6002018-07-30 MEDIUM 5.9 CVE-2018-0497 ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuit… Debian Linux 2.1.14 / 2.7.5+ Fix from $1,6002018-07-28 HIGH 7.5 CVE-2016-9578 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send … Debian Linux 0.13.90+ Fix from $1,9502018-07-27 HIGH 8.8 CVE-2016-9577 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th… Debian Linux 0.13.90+ Fix from $1,9502018-07-27 CRITICAL 9.8 CVE-2017-2640EPSS 6% An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla… Debian Linux 2.12.0+ Fix from $2,3002018-07-27 HIGH 7.0 CVE-2017-2624 It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the co… Debian Linux after 1.19.4 Fix from $1,9502018-07-27 HIGH 7.5 CVE-2017-15120EPSS 52% An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing… Debian Linux 4.0.8+ Fix from $1,9502018-07-27 HIGH 7.4 CVE-2017-12151 A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The con… Debian Linux 4.4.16 / 4.5.14+ Fix from $1,9502018-07-27 MEDIUM 5.5 CVE-2015-9261 huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during a… Debian Linux 1.27.2+ Fix from $1,6002018-07-26 MEDIUM 5.4 CVE-2018-0618 Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via uns… Debian Linux after 2.1.26 Fix from $1,6002018-07-26 HIGH 7.8 CVE-2018-10900EPSS 5% Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can b… Debian Linux 1.2.6+ Fix from $1,9502018-07-26 MEDIUM 5.5 CVE-2018-1002200EPSS 13% plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an arc… Debian Linux 3.6.0+ Fix from $1,6002018-07-25 MEDIUM 5.5 CVE-2018-10880 Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_updat… Debian Linux 4.17.6+ Fix from $1,6002018-07-25