Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2018-0489 Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatu… Debian Linux 1.6.4 / 6.7.2+ Fix from $1,6002018-02-27 HIGH 7.5 CVE-2018-7490EPSS 69% uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal. Debian Linux 2.0.17+ Fix from $1,9502018-02-26 CRITICAL 9.8 CVE-2018-7489EPSS 20% FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an in… Debian Linux 2.7.9.3 / 2.8.11.1+ Fix from $2,3002018-02-26 HIGH 7.8 CVE-2018-7487 There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or poss… Debian Linux No fix yet Fix from $1,9502018-02-26 MEDIUM 6.5 CVE-2018-7456 A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0a… Debian Linux Patch available Fix from $1,6002018-02-24 MEDIUM 6.5 CVE-2018-7443 The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows r… Debian Linux No fix yet Fix from $1,6002018-02-23 CRITICAL 9.8 CVE-2018-7440 An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo… Debian Linux after 1.75.3 Fix from $2,3002018-02-23 HIGH 8.8 CVE-2018-7435 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function. Debian Linux 1.0.5+ Fix from $1,9502018-02-23 HIGH 8.8 CVE-2018-7436 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function. Debian Linux 1.0.5+ Fix from $1,9502018-02-23 HIGH 8.8 CVE-2018-7437 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function. Debian Linux 1.0.5+ Fix from $1,9502018-02-23 HIGH 8.8 CVE-2018-7438 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function. Debian Linux 1.0.5+ Fix from $1,9502018-02-23 HIGH 8.8 CVE-2018-7439 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record. Debian Linux 1.0.5+ Fix from $1,9502018-02-23 HIGH 7.5 CVE-2018-7284EPSS 58% A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.1… Debian Linux after 15.2.1 Fix from $1,9502018-02-22 MEDIUM 6.5 CVE-2018-7286EPSS 38% An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pj… Debian Linux after 15.2.1 Fix from $1,6002018-02-22 MEDIUM 5.9 CVE-2015-5314 The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough fo… Debian Linux 2.6+ Fix from $1,6002018-02-21 MEDIUM 5.9 CVE-2015-5315 The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for … Debian Linux 2.6+ Fix from $1,6002018-02-21 MEDIUM 5.9 CVE-2015-5316 The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configurat… Debian Linux 2.6+ Fix from $1,6002018-02-21 HIGH 7.8 CVE-2018-7253 The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buff… Debian Linux Patch available Fix from $1,9502018-02-19 HIGH 7.8 CVE-2018-7254EPSS 10% The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-… Debian Linux Patch available Fix from $1,9502018-02-19 CRITICAL 9.8 CVE-2017-7375 A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida… Debian Linux after 2.9.4 Fix from $2,3002018-02-19 CRITICAL 9.8 CVE-2017-7376EPSS 23% Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects. Debian Linux 2.9.5+ Fix from $2,3002018-02-19 CRITICAL 9.8 CVE-2018-7225EPSS 6% An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to a… Debian Linux No fix yet Fix from $2,3002018-02-19 CRITICAL 9.8 CVE-2018-5379EPSS 38% The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a… Debian Linux after 1.2.2 Fix from $2,3002018-02-19 MEDIUM 5.9 CVE-2018-5378EPSS 74% The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is i… Debian Linux after 1.2.2 Fix from $1,6002018-02-19 HIGH 7.5 CVE-2017-18190 A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP c… Debian Linux 2.2.2+ Fix from $1,9502018-02-16 CRITICAL 9.8 CVE-2018-7186 Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a… Debian Linux 1.75.3+ Fix from $2,3002018-02-16 CRITICAL 9.8 CVE-2018-7053 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected orde… Debian Linux 1.0.7+ Fix from $2,3002018-02-15 HIGH 7.5 CVE-2018-7050 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick. Debian Linux 1.0.7+ Fix from $1,9502018-02-15 HIGH 7.5 CVE-2018-7051 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme str… Debian Linux 1.0.7+ Fix from $1,9502018-02-15 HIGH 7.5 CVE-2017-18189EPSS 5% In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a … Debian Linux after 14.4.2 Fix from $1,9502018-02-15