Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.5
CVE-2021-37615

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37620

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Fix: 0.27.5+
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37621

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37622

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37616

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37618

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37619

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-32815

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is t…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-34334

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is trigge…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora MEDIUM 5.5
CVE-2021-37623

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found…

Fix: after 0.27.4
Fix from $1,600 2021-08-09
Fedora HIGH 7.5
CVE-2021-3673

A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and…

Patch available
Fix from $1,950 2021-08-02
Fedora CRITICAL 9.8
CVE-2021-32810

crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the…

Fix: 0.7.4 / 0.8.1+
Fix from $2,300 2021-08-02
Fedora MEDIUM 6.1
CVE-2021-37746

textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accept…

Fix: 3.18.0+
Fix from $1,600 2021-07-30
Fedora HIGH 7.5
CVE-2021-36386

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers…

Fix: 6.4.20+
Fix from $1,950 2021-07-30
Fedora MEDIUM 6.1
CVE-2021-23414

This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.

Fix: 7.14.3+
Fix from $1,600 2021-07-28
Fedora MEDIUM 6.1
CVE-2021-32792

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenti…

Fix: 2.4.9+
Fix from $1,600 2021-07-26
Fedora MEDIUM 5.9
CVE-2021-32791

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenti…

Fix: 2.4.9+
Fix from $1,600 2021-07-26
Fedora MEDIUM 6.1
CVE-2021-32786

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenti…

Fix: 2.4.9+
Fix from $1,600 2021-07-22
Fedora MEDIUM 5.5
CVE-2021-37220

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. T…

Fix: after 1.18.1
Fix from $1,600 2021-07-21
Fedora MEDIUM 5.9
CVE-2021-2389EPSS 8%

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 a…

Fix: 10.2.40 / 10.3.31+
Fix from $1,600 2021-07-21
Fedora MEDIUM 5.0
CVE-2021-2385

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.34 and prior…

Fix: after 8.0.25
Fix from $1,600 2021-07-21
Fedora MEDIUM 5.5
CVE-2021-33910EPSS 9%

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and all…

Fix: 246.15 / 247.8+
Fix from $1,600 2021-07-20
Fedora HIGH 8.8
CVE-2021-3246

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

Patch available
Fix from $1,950 2021-07-20
Fedora MEDIUM 5.5
CVE-2021-36979

Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb).

Patch available
Fix from $1,600 2021-07-20
Fedora HIGH 7.8
CVE-2020-36430

libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer dat…

Fix: 0.15.1+
Fix from $1,950 2021-07-20
Fedora MEDIUM 6.5
CVE-2021-36976

libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

Fix: 8.2.12 / 8.5+
Fix from $1,600 2021-07-20
Fedora MEDIUM 6.3
CVE-2021-32760

containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted c…

Fix: 1.4.8 / 1.5.4+
Fix from $1,600 2021-07-19
Fedora HIGH 8.1
CVE-2021-32749

fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0…

Fix: 0.10.7 / 0.11.3+
Fix from $1,950 2021-07-16
Fedora MEDIUM 6.5
CVE-2021-36740

Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This …

Fix: 6.0.8+
Fix from $1,600 2021-07-14
Fedora HIGH 7.5
CVE-2021-36377

Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.

Fix: 2.14.2 / 2.15.2+
Fix from $1,950 2021-07-12