Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2017-8820 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers… Debian Linux 0.2.5.16 / 0.2.8.17+ Fix from $1,9502017-12-03 HIGH 7.5 CVE-2017-8821 In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can … Debian Linux 0.2.5.16 / 0.2.8.17+ Fix from $1,9502017-12-03 HIGH 7.5 CVE-2017-16612EPSS 5% libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with program… Debian Linux after 1.1.14 Fix from $1,9502017-12-01 MEDIUM 5.5 CVE-2017-16611 In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, w… Debian Linux 1.5.4 / 2.0.3+ Fix from $1,6002017-12-01 MEDIUM 5.5 CVE-2017-17087 fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group owners… Debian Linux 8.0.1263+ Fix from $1,6002017-12-01 HIGH 8.8 CVE-2017-14176EPSS 6% Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash chara… Debian Linux after 2.7.0 Fix from $1,9502017-11-27 HIGH 8.1 CVE-2017-8028 In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind… Debian Linux Mitigation only Fix from $1,9502017-11-27 CRITICAL 9.8 CVE-2017-16943EPSS 47% The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of… Debian Linux Patch available Fix from $2,3002017-11-25 HIGH 7.5 CVE-2017-16944EPSS 63% The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop an… Debian Linux No fix yet Fix from $1,9502017-11-25 HIGH 8.4 CVE-2017-16927 The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, wh… Debian Linux after 0.9.4 Fix from $1,9502017-11-23 HIGH 8.8 CVE-2017-16664 Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In t… Debian Linux 3.3.20 / 4.0.26+ Fix from $1,9502017-11-21 CRITICAL 9.8 CVE-2017-16613EPSS 8% An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and … Debian Linux after 2.15.1 Fix from $2,3002017-11-21 CRITICAL 9.8 CVE-2017-16840 The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorre… Debian Linux Patch available Fix from $2,3002017-11-21 HIGH 7.8 CVE-2017-2896 An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a mem… Debian Linux Mitigation only Fix from $1,9502017-11-20 HIGH 7.8 CVE-2017-2919 An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause … Debian Linux Mitigation only Fix from $1,9502017-11-20 HIGH 7.1 CVE-2017-16899 An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with… Debian Linux Mitigation only Fix from $1,9502017-11-20 HIGH 8.8 CVE-2017-16544EPSS 6% In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames i… Debian Linux after 1.27.2 Fix from $1,9502017-11-20 CRITICAL 10.0 CVE-2017-16845 hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. Debian Linux after 2.11.2 Fix from $2,3002017-11-17 CRITICAL 9.8 CVE-2017-16872 An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cse… Debian Linux 2.7.1+ Fix from $2,3002017-11-17 HIGH 7.8 CVE-2017-1000229 Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service. Debian Linux No fix yet Fix from $1,9502017-11-17 HIGH 8.1 CVE-2017-16852 shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly conf… Debian Linux 2.6.1+ Fix from $1,9502017-11-16 HIGH 8.1 CVE-2017-16853 The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly co… Debian Linux 2.6.1+ Fix from $1,9502017-11-16 HIGH 8.8 CVE-2017-15864 In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database … Debian Linux after 3.3.18 Fix from $1,9502017-11-16 CRITICAL 9.1 CVE-2017-8807 vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sen… Debian Linux 4.1.9 / 5.2.1+ Fix from $2,3002017-11-16 HIGH 7.5 CVE-2017-15923 Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing o… Debian Linux 1.7.3+ Fix from $1,9502017-11-15 CRITICAL 9.8 CVE-2017-8809EPSS 8% api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability. Debian Linux after 1.27.3 Fix from $2,3002017-11-15 HIGH 7.5 CVE-2017-8810 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for fai… Debian Linux after 1.27.3 Fix from $1,9502017-11-15 HIGH 7.5 CVE-2017-8814 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a … Debian Linux after 1.27.3 Fix from $1,9502017-11-15 HIGH 7.5 CVE-2017-8815 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rul… Debian Linux after 1.27.3 Fix from $1,9502017-11-15 MEDIUM 6.1 CVE-2017-8808 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sen… Debian Linux after 1.27.3 Fix from $1,6002017-11-15