Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-15572
The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context swi…
Debian Linux
4.18.1+
CRITICAL 9.8
CVE-2018-15494
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
Debian Linux
1.14+
HIGH 7.5
CVE-2018-15501
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packe…
Debian Linux
0.26.6 / 0.27.4+
MEDIUM 5.3
CVE-2018-15473EPSS 99%
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packe…
Debian Linux
after 7.7
MEDIUM 6.5
CVE-2018-15469
An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an…
Debian Linux
after 4.11.0
HIGH 8.8
CVE-2018-10873
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check…
Debian Linux
Patch available
HIGH 8.1
CVE-2018-14348
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
Debian Linux
after 0.41
HIGH 8.8
CVE-2018-15209
ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and …
Debian Linux
No fix yet
HIGH 8.8
CVE-2018-14593
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is …
Debian Linux
after 6.0.9
HIGH 7.5
CVE-2018-14912EPSS 93%
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cg…
Debian Linux
1.2.1+
CRITICAL 9.8
CVE-2015-9262EPSS 6%
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a…
Debian Linux
1.1.15+
HIGH 7.8
CVE-2016-8654
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before…
Debian Linux
2.0.0+
MEDIUM 6.5
CVE-2016-9572
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for de…
Debian Linux
Patch available
MEDIUM 5.3
CVE-2018-14432
In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may by…
Debian Linux
11.0.4+
HIGH 7.4
CVE-2018-8019
When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for r…
Debian Linux
after 1.2.16
HIGH 7.4
CVE-2018-8020
Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multi…
Debian Linux
after 1.2.16
CRITICAL 9.8
CVE-2018-14767EPSS 29%
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…
Debian Linux
5.0.7 / 5.1.4+
MEDIUM 5.5
CVE-2018-10883
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of s…
Debian Linux
4.9.110+
MEDIUM 5.9
CVE-2018-0497
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuit…
Debian Linux
2.1.14 / 2.7.5+
HIGH 7.5
CVE-2016-9578
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send …
Debian Linux
0.13.90+
HIGH 8.8
CVE-2016-9577
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th…
Debian Linux
0.13.90+
CRITICAL 9.8
CVE-2017-2640EPSS 6%
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla…
Debian Linux
2.12.0+
HIGH 7.0
CVE-2017-2624
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the co…
Debian Linux
after 1.19.4
HIGH 7.5
CVE-2017-15120EPSS 52%
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing…
Debian Linux
4.0.8+
HIGH 7.4
CVE-2017-12151
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The con…
Debian Linux
4.4.16 / 4.5.14+
MEDIUM 5.5
CVE-2015-9261
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during a…
Debian Linux
1.27.2+
MEDIUM 5.4
CVE-2018-0618
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via uns…
Debian Linux
after 2.1.26
HIGH 7.8
CVE-2018-10900EPSS 5%
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can b…
Debian Linux
1.2.6+
MEDIUM 5.5
CVE-2018-1002200EPSS 13%
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an arc…
Debian Linux
3.6.0+
MEDIUM 5.5
CVE-2018-10880
Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_updat…
Debian Linux
4.17.6+