Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-0489
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatu…
Debian Linux
1.6.4 / 6.7.2+
HIGH 7.5
CVE-2018-7490EPSS 69%
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
Debian Linux
2.0.17+
CRITICAL 9.8
CVE-2018-7489EPSS 20%
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an in…
Debian Linux
2.7.9.3 / 2.8.11.1+
HIGH 7.8
CVE-2018-7487
There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or poss…
Debian Linux
No fix yet
MEDIUM 6.5
CVE-2018-7456
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0a…
Debian Linux
Patch available
MEDIUM 6.5
CVE-2018-7443
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows r…
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2018-7440
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo…
Debian Linux
after 1.75.3
HIGH 8.8
CVE-2018-7435
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function.
Debian Linux
1.0.5+
HIGH 8.8
CVE-2018-7436
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.
Debian Linux
1.0.5+
HIGH 8.8
CVE-2018-7437
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.
Debian Linux
1.0.5+
HIGH 8.8
CVE-2018-7438
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function.
Debian Linux
1.0.5+
HIGH 8.8
CVE-2018-7439
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.
Debian Linux
1.0.5+
HIGH 7.5
CVE-2018-7284EPSS 58%
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.1…
Debian Linux
after 15.2.1
MEDIUM 6.5
CVE-2018-7286EPSS 38%
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pj…
Debian Linux
after 15.2.1
MEDIUM 5.9
CVE-2015-5314
The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough fo…
Debian Linux
2.6+
MEDIUM 5.9
CVE-2015-5315
The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for …
Debian Linux
2.6+
MEDIUM 5.9
CVE-2015-5316
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configurat…
Debian Linux
2.6+
HIGH 7.8
CVE-2018-7253
The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buff…
Debian Linux
Patch available
HIGH 7.8
CVE-2018-7254EPSS 10%
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2017-7375
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…
Debian Linux
after 2.9.4
CRITICAL 9.8
CVE-2017-7376EPSS 23%
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
Debian Linux
2.9.5+
CRITICAL 9.8
CVE-2018-7225EPSS 6%
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to a…
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2018-5379EPSS 38%
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a…
Debian Linux
after 1.2.2
MEDIUM 5.9
CVE-2018-5378EPSS 74%
The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is i…
Debian Linux
after 1.2.2
HIGH 7.5
CVE-2017-18190
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP c…
Debian Linux
2.2.2+
CRITICAL 9.8
CVE-2018-7186
Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a…
Debian Linux
1.75.3+
CRITICAL 9.8
CVE-2018-7053
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected orde…
Debian Linux
1.0.7+
HIGH 7.5
CVE-2018-7050
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.
Debian Linux
1.0.7+
HIGH 7.5
CVE-2018-7051
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme str…
Debian Linux
1.0.7+
HIGH 7.5
CVE-2017-18189EPSS 5%
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a …
Debian Linux
after 14.4.2