Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.3
CVE-2021-28090

Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.

Fix: 0.3.5.14 / 0.4.4.8+
Fix from $1,600 2021-03-19
Fedora MEDIUM 6.0
CVE-2021-3416

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs…

Fix: after 5.2.0
Fix from $1,600 2021-03-18
Fedora HIGH 7.5
CVE-2020-26797

Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.

Fix: 20.08+
Fix from $1,950 2021-03-18
Fedora MEDIUM 5.5
CVE-2021-28650

autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extrac…

Fix: 0.3.1+
Fix from $1,600 2021-03-17
Fedora HIGH 7.5
CVE-2021-28543

Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not aff…

Fix: 0.17.1+
Fix from $1,950 2021-03-16
Fedora HIGH 8.1
CVE-2021-21367

Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When t…

Fix: 2.3.5+
Fix from $1,950 2021-03-12
Fedora HIGH 7.5
CVE-2020-36278

Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.

Fix: 1.80.0+
Fix from $1,950 2021-03-12
Fedora HIGH 7.5
CVE-2020-36279

Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.

Fix: 1.80.0+
Fix from $1,950 2021-03-12
Fedora HIGH 7.5
CVE-2020-36280

Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.

Fix: 1.80.0+
Fix from $1,950 2021-03-12
Fedora HIGH 7.5
CVE-2020-36277

Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.

Fix: 1.80.0+
Fix from $1,950 2021-03-11
Fedora MEDIUM 6.3
CVE-2021-21334

In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation …

Fix: 1.3.10 / 1.4.4+
Fix from $1,600 2021-03-10
Fedora HIGH 8.1
CVE-2021-21772

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3…

No fix yet
Fix from $1,950 2021-03-10
Fedora MEDIUM 6.5
CVE-2021-20205

Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF …

Patch available
Fix from $1,600 2021-03-10
Fedora MEDIUM 5.3
CVE-2021-28116EPSS 13%

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol dat…

Fix: after 5.0.5
Fix from $1,600 2021-03-09
Fedora MEDIUM 5.5
CVE-2020-35522

In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service…

Fix: 4.2.0+
Fix from $1,600 2021-03-09
Fedora CRITICAL 9.8
CVE-2021-3420

A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memali…

Fix: 4.0.0+
Fix from $2,300 2021-03-05
Fedora HIGH 7.1
CVE-2021-28041

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a…

Fix: 8.5+
Fix from $1,950 2021-03-05
Fedora CRITICAL 9.8
CVE-2020-28636

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2…

Mitigation only
Fix from $2,300 2021-03-04
Fedora CRITICAL 9.8
CVE-2020-35628

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2…

Mitigation only
Fix from $2,300 2021-03-04
Fedora CRITICAL 9.8
CVE-2020-28601

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/…

Mitigation only
Fix from $2,300 2021-03-04
Fedora MEDIUM 6.5
CVE-2020-28591

An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 9…

No fix yet
Fix from $1,600 2021-03-03
Fedora HIGH 7.5
CVE-2021-26813

markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string…

Fix: 2.4.0+
Fix from $1,950 2021-03-03
Fedora CRITICAL 9.8
CVE-2021-3148EPSS 8%

An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() comman…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Fedora CRITICAL 9.8
CVE-2021-3197EPSS 72%

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Fedora CRITICAL 9.1
CVE-2021-3144EPSS 5%

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minion…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Fedora CRITICAL 9.8
CVE-2021-25281EPSS 73%

An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attac…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Fedora CRITICAL 9.8
CVE-2021-25283EPSS 11%

An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Fedora CRITICAL 9.1
CVE-2021-25282EPSS 92%

An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Fedora HIGH 7.8
CVE-2020-28243

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. Thi…

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,950 2021-02-27
Fedora HIGH 7.4
CVE-2020-35662

In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,950 2021-02-27