Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2018-12891 An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reason Xen explicitly checks for t… Debian Linux after 4.10.1 Fix from $1,6002018-07-02 MEDIUM 6.5 CVE-2018-12893 An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen livelocking with debug except… Debian Linux after 4.10.0 Fix from $1,6002018-07-02 HIGH 8.1 CVE-2018-13054 An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) ot… Debian Linux after 3.8.6 Fix from $1,9502018-07-02 CRITICAL 9.8 CVE-2018-13043 scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co… Devscripts after 2.18.3 Fix from $2,3002018-07-01 CRITICAL 9.8 CVE-2018-13005 An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. Debian Linux No fix yet Fix from $2,3002018-06-29 CRITICAL 9.8 CVE-2018-13006 An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. Debian Linux Patch available Fix from $2,3002018-06-29 CRITICAL 9.8 CVE-2017-7658EPSS 21% In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented w… Debian Linux 9.3.24 / 9.4.11+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-1000544 rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary … Debian Linux after 1.2.1 Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-1000550 The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that… Debian Linux 6.2.32+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-1000517EPSS 33% BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wge… Debian Linux 1.29.0+ Fix from $2,3002018-06-26 MEDIUM 6.1 CVE-2018-1000528EPSS 46% GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password fo… Debian Linux Patch available Fix from $1,6002018-06-26 CRITICAL 9.8 CVE-2017-7657EPSS 16% In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transf… Debian Linux 9.3.24 / 9.4.11+ Fix from $2,3002018-06-26 HIGH 7.5 CVE-2017-7656EPSS 6% In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0… Debian Linux 9.3.24 / 9.4.11+ Fix from $1,9502018-06-26 HIGH 7.5 CVE-2018-10852 The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can s… Debian Linux 1.16.3+ Fix from $1,9502018-06-26 HIGH 7.5 CVE-2017-2669 Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sen… Debian Linux after 2.2.28 Fix from $1,9502018-06-21 CRITICAL 9.8 CVE-2018-12601 There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other im… Debian Linux Patch available Fix from $2,3002018-06-20 HIGH 8.8 CVE-2018-10841 glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-… Debian Linux 4.1.8+ Fix from $1,9502018-06-20 HIGH 7.5 CVE-2018-10811EPSS 6% strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. Debian Linux 5.6.3+ Fix from $1,9502018-06-19 HIGH 8.8 CVE-2018-12565 An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote … Debian Linux after 2018.4 Fix from $1,9502018-06-19 MEDIUM 6.5 CVE-2018-12564 An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that wil… Debian Linux 2018.5.post1+ Fix from $1,6002018-06-19 HIGH 7.0 CVE-2018-12029 A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard pass… Debian Linux 5.3.2+ Fix from $1,9502018-06-17 MEDIUM 5.5 CVE-2018-12495 The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove… Debian Linux No fix yet Fix from $1,6002018-06-15 MEDIUM 6.5 CVE-2018-12458 An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violati… Debian Linux Patch available Fix from $1,6002018-06-15 MEDIUM 5.9 CVE-2018-10850 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a cras… Debian Linux Patch available Fix from $1,6002018-06-13 HIGH 8.8 CVE-2018-12264 Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.… Debian Linux No fix yet Fix from $1,9502018-06-13 HIGH 8.8 CVE-2018-12265 Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp. Debian Linux No fix yet Fix from $1,9502018-06-13 HIGH 7.5 CVE-2018-0496 Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allo… Debian Linux 3.14+ Fix from $1,9502018-06-12 HIGH 7.5 CVE-2018-12249 An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported i… Debian Linux Patch available Fix from $1,9502018-06-12 MEDIUM 5.3 CVE-2018-12227 An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert bef… Debian Linux 13.21.1 / 14.7.7+ Fix from $1,6002018-06-12 HIGH 8.1 CVE-2018-5178 A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requi… Debian Linux 52.8.0+ Fix from $1,9502018-06-11