Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2018-5683 The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by… Debian Linux Patch available Fix from $1,6002018-01-23 MEDIUM 6.1 CVE-2018-5950 Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a … Debian Linux Patch available Fix from $1,6002018-01-23 MEDIUM 5.3 CVE-2017-15105 A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be u… Debian Linux 1.6.8+ Fix from $1,6002018-01-23 HIGH 7.5 CVE-2018-6003 An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder lea… Debian Linux after 4.12 Fix from $1,9502018-01-22 HIGH 8.1 CVE-2018-5968EPSS 7% FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C… Debian Linux 2.6.7.3 / 2.7.9.2+ Fix from $1,9502018-01-22 HIGH 7.5 CVE-2016-10708EPSS 16% sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NE… Debian Linux 7.4+ Fix from $1,9502018-01-21 HIGH 7.8 CVE-2017-15108 spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the … Debian Linux after 0.17.0 Fix from $1,9502018-01-20 MEDIUM 6.5 CVE-2018-5784 In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this v… Debian Linux Patch available Fix from $1,6002018-01-19 MEDIUM 6.5 CVE-2018-5785 In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote a… Debian Linux No fix yet Fix from $1,6002018-01-19 MEDIUM 5.5 CVE-2018-5786 In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could le… Debian Linux Patch available Fix from $1,6002018-01-19 MEDIUM 6.5 CVE-2017-12197 It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di… Debian Linux after 1.8 Fix from $1,6002018-01-18 HIGH 7.5 CVE-2018-5764EPSS 6% The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attacker… Debian Linux 3.1.3+ Fix from $1,9502018-01-17 MEDIUM 5.5 CVE-2018-5747 In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerabi… Debian Linux No fix yet Fix from $1,6002018-01-17 CRITICAL 9.6 CVE-2018-5704 Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attacker… Debian Linux Patch available Fix from $2,3002018-01-16 HIGH 8.8 CVE-2018-5702EPSS 12% Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote att… Debian Linux after 2.92 Fix from $1,9502018-01-15 MEDIUM 6.5 CVE-2018-5685 In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage… Debian Linux Patch available Fix from $1,6002018-01-14 MEDIUM 5.5 CVE-2018-5686 In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not co… Debian Linux No fix yet Fix from $1,6002018-01-14 MEDIUM 6.5 CVE-2018-0486 Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signature… Debian Linux 1.6.3+ Fix from $1,6002018-01-13 HIGH 7.5 CVE-2017-13194 A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android … Debian Linux Patch available Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2017-17485EPSS 50% FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C… Debian Linux 2.6.7.3 / 2.7.9.2+ Fix from $2,3002018-01-10 HIGH 8.8 CVE-2017-18026 Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which … Debian Linux 3.2.9 / 3.3.6+ Fix from $1,9502018-01-10 CRITICAL 9.8 CVE-2015-2320 The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. Debian Linux 3.12.1+ Fix from $2,3002018-01-08 HIGH 8.1 CVE-2015-2318 The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by le… Debian Linux 3.12.1+ Fix from $1,9502018-01-08 MEDIUM 6.5 CVE-2018-5294 In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers coul… Debian Linux Mitigation only Fix from $1,6002018-01-08 MEDIUM 5.5 CVE-2018-5268 In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing … Debian Linux No fix yet Fix from $1,6002018-01-08 MEDIUM 5.5 CVE-2018-5269 In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast. Debian Linux No fix yet Fix from $1,6002018-01-08 CRITICAL 9.8 CVE-2018-5206 When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer. Debian Linux 1.0.6+ Fix from $2,3002018-01-06 CRITICAL 9.8 CVE-2018-5208 In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. Debian Linux 1.0.6+ Fix from $2,3002018-01-06 HIGH 7.5 CVE-2018-5205 When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string. Debian Linux 1.0.6+ Fix from $1,9502018-01-06 HIGH 7.5 CVE-2018-5207 When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string. Debian Linux 1.0.6+ Fix from $1,9502018-01-06