Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2017-15572 In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, b… Debian Linux after 3.2.5 Fix from $1,9502017-10-18 HIGH 7.5 CVE-2017-15576 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive info… Debian Linux after 3.2.5 Fix from $1,9502017-10-18 HIGH 7.5 CVE-2017-15577 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information. Debian Linux after 3.2.5 Fix from $1,9502017-10-18 HIGH 7.3 CVE-2017-15575 In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which … Debian Linux after 3.2.5 Fix from $1,9502017-10-18 MEDIUM 6.1 CVE-2017-15568 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a c… Debian Linux after 3.2.7 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15569 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a craft… Debian Linux after 3.2.7 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15570 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data. Debian Linux after 3.2.7 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15571 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data. Debian Linux after 3.2.7 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15573 In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content. Debian Linux after 3.2.5 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15574 In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment. Debian Linux after 3.2.5 Fix from $1,6002017-10-18 HIGH 8.8 CVE-2017-15565 In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document. Debian Linux No fix yet Fix from $1,9502017-10-17 CRITICAL 9.1 CVE-2017-8805 Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a… Ftpsync after 20171016 Fix from $2,3002017-10-17 HIGH 8.8 CVE-2015-7504 Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (insta… Debian Linux after 2.4.1 Fix from $1,9502017-10-16 MEDIUM 5.5 CVE-2017-15370 There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of… Debian Linux No fix yet Fix from $1,6002017-10-16 MEDIUM 5.5 CVE-2017-15371 There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a… Debian Linux No fix yet Fix from $1,6002017-10-16 MEDIUM 5.5 CVE-2017-15372 There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will le… Debian Linux No fix yet Fix from $1,6002017-10-16 HIGH 8.8 CVE-2017-2887 An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can c… Debian Linux Mitigation only Fix from $1,9502017-10-11 CRITICAL 9.8 CVE-2017-0903EPSS 16% RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio… Debian Linux Patch available Fix from $2,3002017-10-11 HIGH 8.8 CVE-2017-15238 ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage. Debian Linux Patch available Fix from $1,9502017-10-11 HIGH 7.8 CVE-2017-13723 In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing c… Debian Linux after 1.19.3 Fix from $1,9502017-10-10 CRITICAL 9.8 CVE-2017-1000116EPSS 6% Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks. Debian Linux 4.3+ Fix from $2,3002017-10-05 HIGH 7.5 CVE-2017-1000115 Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository Debian Linux 4.3+ Fix from $1,9502017-10-05 MEDIUM 6.5 CVE-2017-14994 ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted D… Debian Linux Patch available Fix from $1,6002017-10-04 MEDIUM 6.5 CVE-2017-14997 GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTI… Debian Linux Patch available Fix from $1,6002017-10-04 HIGH 7.5 CVE-2017-14975 The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is n… Debian Linux No fix yet Fix from $1,9502017-10-02 HIGH 7.5 CVE-2017-14976 The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font d… Debian Linux Patch available Fix from $1,9502017-10-02 HIGH 7.5 CVE-2017-14977 The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of… Debian Linux No fix yet Fix from $1,9502017-10-02 MEDIUM 5.5 CVE-2017-14926 In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document. Debian Linux Mitigation only Fix from $1,6002017-09-30 MEDIUM 5.5 CVE-2017-14928 In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document. Debian Linux Mitigation only Fix from $1,6002017-09-30 MEDIUM 5.5 CVE-2017-14737 A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker … Debian Linux after 1.10.16 Fix from $1,6002017-09-26