Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2017-8811 The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling… Debian Linux after 1.27.3 Fix from $1,6002017-11-15 MEDIUM 5.3 CVE-2017-8812 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attr… Debian Linux after 1.27.3 Fix from $1,6002017-11-15 HIGH 7.8 CVE-2017-16651 KEVEPSS 37% Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, i… Debian Linux after 1.1.9 Fix from $1,9502017-11-09 HIGH 8.8 CVE-2017-16669 coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or poss… Debian Linux Patch available Fix from $1,9502017-11-09 HIGH 8.8 CVE-2017-15672 The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via … Debian Linux after 3.3.4 Fix from $1,9502017-11-06 HIGH 8.8 CVE-2017-16352EPSS 15% GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Descri… Debian Linux No fix yet Fix from $1,9502017-11-01 MEDIUM 6.5 CVE-2017-16353EPSS 14% GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil… Debian Linux No fix yet Fix from $1,6002017-11-01 CRITICAL 9.1 CVE-2017-1000257EPSS 6% An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl woul… Debian Linux after 7.56.0 Fix from $2,3002017-10-31 HIGH 7.5 CVE-2017-16227EPSS 19% The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT… Debian Linux after 1.2.1 Fix from $1,9502017-10-29 MEDIUM 5.5 CVE-2017-15953 bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file. Debian Linux Patch available Fix from $1,6002017-10-28 MEDIUM 5.5 CVE-2017-15954 bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processin… Debian Linux Patch available Fix from $1,6002017-10-28 MEDIUM 5.5 CVE-2017-15955 bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a ma… Debian Linux Patch available Fix from $1,6002017-10-28 HIGH 8.8 CVE-2017-13089EPSS 80% The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget b… Debian Linux after 1.19.1 Fix from $1,9502017-10-27 HIGH 8.8 CVE-2017-13090EPSS 37% The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser … Debian Linux after 1.19.1 Fix from $1,9502017-10-27 HIGH 8.8 CVE-2017-15930 In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelP… Debian Linux Patch available Fix from $1,9502017-10-27 HIGH 7.8 CVE-2017-15924 In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration req… Debian Linux Patch available Fix from $1,9502017-10-27 MEDIUM 6.5 CVE-2017-5094 Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacke… Debian Linux 60.0.3112.78+ Fix from $1,6002017-10-27 MEDIUM 5.3 CVE-2017-15906 The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers … Debian Linux 7.6+ Fix from $1,6002017-10-26 MEDIUM 5.5 CVE-2017-15873 The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access vio… Debian Linux Patch available Fix from $1,6002017-10-24 HIGH 7.5 CVE-2017-15721 In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue… Debian Linux after 1.0.4 Fix from $1,9502017-10-22 HIGH 7.5 CVE-2017-15723 In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message. Debian Linux after 1.0.4 Fix from $1,9502017-10-22 MEDIUM 5.9 CVE-2017-15722 In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string. Debian Linux after 1.0.4 Fix from $1,6002017-10-22 HIGH 7.5 CVE-2015-5177EPSS 6% Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service… Debian Linux Patch available Fix from $1,9502017-10-22 HIGH 7.8 CVE-2013-6049 apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors. Debian Linux Mitigation only Fix from $1,9502017-10-20 MEDIUM 5.5 CVE-2017-15642 In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file. Debian Linux Mitigation only Fix from $1,6002017-10-19 MEDIUM 5.3 CVE-2017-10347 Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u… Debian Linux Patch available Fix from $1,6002017-10-19 CRITICAL 9.6 CVE-2017-10285 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u1… Debian Linux Patch available Fix from $2,3002017-10-19 MEDIUM 5.3 CVE-2017-10281 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affect… Debian Linux Patch available Fix from $1,6002017-10-19 MEDIUM 6.8 CVE-2017-10274 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u15… Debian Linux Patch available Fix from $1,6002017-10-19 MEDIUM 6.5 CVE-2015-1239 Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to ca… Debian Linux 2.1.1+ Fix from $1,6002017-10-18