Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-18187 In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity… Debian Linux 2.7.0+ Fix from $2,3002018-02-14 CRITICAL 9.8 CVE-2018-0487 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ov… Debian Linux 1.3.22 / 2.1.10+ Fix from $2,3002018-02-13 CRITICAL 9.8 CVE-2018-0488 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute a… Debian Linux 1.3.22 / 2.1.10+ Fix from $2,3002018-02-13 HIGH 8.8 CVE-2018-1000041 GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can… Debian Linux 2.41.2+ Fix from $1,9502018-02-09 HIGH 7.8 CVE-2018-1000051 Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This a… Debian Linux Patch available Fix from $1,9502018-02-09 HIGH 7.5 CVE-2018-1000024EPSS 8% The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ES… Debian Linux after 4.0.22 Fix from $1,9502018-02-09 HIGH 7.5 CVE-2018-1000027EPSS 13% The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Resp… Debian Linux 4.0.23+ Fix from $1,9502018-02-09 CRITICAL 9.8 CVE-2018-6871EPSS 23% LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.… Debian Linux Patch available Fix from $2,3002018-02-09 MEDIUM 6.5 CVE-2018-6869 In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attacker… Debian Linux Patch available Fix from $1,6002018-02-09 CRITICAL 9.8 CVE-2018-6789 KEVEPSS 82% An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may h… Debian Linux 4.90.1+ Fix from $2,3002018-02-08 HIGH 8.8 CVE-2018-6799 The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap ove… Debian Linux 1.3.28+ Fix from $1,9502018-02-07 MEDIUM 5.3 CVE-2018-6794EPSS 24% Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow… Debian Linux 4.0.4+ Fix from $1,6002018-02-07 MEDIUM 6.8 CVE-2018-6791 An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $(… Debian Linux 5.12.0+ Fix from $1,6002018-02-07 HIGH 7.8 CVE-2018-6767 A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-o… Debian Linux Patch available Fix from $1,9502018-02-06 CRITICAL 9.8 CVE-2017-15095EPSS 8% A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo… Debian Linux 2.6.7.2 / 2.7.9.2+ Fix from $2,3002018-02-06 CRITICAL 9.8 CVE-2017-7525EPSS 38% A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user … Debian Linux 2.6.7.1 / 2.7.9.1+ Fix from $2,3002018-02-06 MEDIUM 6.5 CVE-2018-6621 The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) v… Debian Linux after 3.2 Fix from $1,6002018-02-05 MEDIUM 5.5 CVE-2018-6616 In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerabili… Debian Linux No fix yet Fix from $1,6002018-02-04 CRITICAL 9.1 CVE-2018-6596 webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al… Debian Linux 1.2.1+ Fix from $2,3002018-02-03 HIGH 8.6 CVE-2017-18123 The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download… Debian Linux after 2017-02-19e Fix from $1,9502018-02-03 HIGH 7.5 CVE-2018-6594 lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive informati… Debian Linux after 2.6.1 Fix from $1,9502018-02-03 HIGH 8.1 CVE-2017-18122 A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as v… Debian Linux after 1.14.16 Fix from $1,9502018-02-02 MEDIUM 6.1 CVE-2017-18121 The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that cou… Debian Linux after 1.14.15 Fix from $1,6002018-02-02 MEDIUM 5.5 CVE-2018-6544 pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which … Debian Linux No fix yet Fix from $1,6002018-02-02 CRITICAL 9.8 CVE-2018-6521 The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. T… Debian Linux 1.15.2+ Fix from $2,3002018-02-02 HIGH 7.5 CVE-2018-6519 The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for… Debian Linux 1.10.4 / 2.3.5+ Fix from $1,9502018-02-02 MEDIUM 5.5 CVE-2017-18043 Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash). Debian Linux after 2.10.1 Fix from $1,6002018-01-31 HIGH 7.8 CVE-2018-5996 Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruption… Debian Linux 18.00 / 18.0+ Fix from $1,9502018-01-31 MEDIUM 5.3 CVE-2011-2902 zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, wh… Debian Linux 3.02-19+ Fix from $1,6002018-01-30 HIGH 7.8 CVE-2017-17969 Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a de… Debian Linux 18.00 / 18.0+ Fix from $1,9502018-01-30