Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.9
CVE-2020-28972

In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SS…

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,600 2021-02-27
Fedora HIGH 7.5
CVE-2021-27803

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could …

Fix: 2.10+
Fix from $1,950 2021-02-26
Fedora MEDIUM 6.5
CVE-2021-21274

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.25.0+
Fix from $1,600 2021-02-26
Fedora MEDIUM 6.1
CVE-2021-21273

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.25.0+
Fix from $1,600 2021-02-26
Fedora MEDIUM 6.7
CVE-2020-24455

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access…

Fix: 2.4.3 / 3.0.1+
Fix from $1,600 2021-02-26
Fedora HIGH 8.1
CVE-2021-26701EPSS 30%

.NET Core Remote Code Execution Vulnerability

Fix: 2.1.28 / 3.1.15+
Fix from $1,950 2021-02-25
Fedora CRITICAL 9.8
CVE-2021-3406

A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the …

Fix: after 5.8.1
Fix from $2,300 2021-02-25
Fedora HIGH 7.8
CVE-2020-28599

A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially craf…

Fix: after 2021.01
Fix from $1,950 2021-02-24
Fedora MEDIUM 5.5
CVE-2021-3407EPSS 50%

A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.

Mitigation only
Fix from $1,600 2021-02-23
Fedora MEDIUM 6.5
CVE-2021-3405

A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in…

Fix: 1.4.2+
Fix from $1,600 2021-02-23
Fedora MEDIUM 5.5
CVE-2021-26927

A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.

Fix: 2.0.25+
Fix from $1,600 2021-02-23
Fedora HIGH 7.1
CVE-2021-26926

A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or …

Fix: 2.0.25+
Fix from $1,950 2021-02-23
Fedora HIGH 8.8
CVE-2021-21157EPSS 9%

Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 88.0.705.74 / 88.0.4324.182+
Fix from $1,950 2021-02-22
Fedora MEDIUM 6.5
CVE-2020-28463

All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & tr…

No fix yet
Fix from $1,600 2021-02-18
Fedora MEDIUM 5.5
CVE-2021-26933

An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means …

Fix: after 4.14.1
Fix from $1,600 2021-02-17
Fedora HIGH 7.5
CVE-2021-27218

An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a…

Fix: 2.66.7 / 2.67.4+
Fix from $1,950 2021-02-15
Fedora HIGH 7.5
CVE-2021-27219

An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms du…

Fix: 2.66.6 / 2.67.3+
Fix from $1,950 2021-02-15
Fedora HIGH 7.8
CVE-2019-19005

A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after…

Patch available
Fix from $1,950 2021-02-11
Fedora HIGH 7.5
CVE-2020-13578

A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead …

No fix yet
Fix from $1,950 2021-02-10
Fedora CRITICAL 9.8
CVE-2020-13576EPSS 6%

A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead t…

No fix yet
Fix from $2,300 2021-02-10
Fedora HIGH 7.5
CVE-2020-13574

A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead …

No fix yet
Fix from $1,950 2021-02-10
Fedora HIGH 7.5
CVE-2020-13575

A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lea…

No fix yet
Fix from $1,950 2021-02-10
Fedora HIGH 7.5
CVE-2020-13577

A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead …

No fix yet
Fix from $1,950 2021-02-10
Fedora HIGH 7.5
CVE-2021-0326

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if …

Patch available
Fix from $1,950 2021-02-10
Fedora MEDIUM 5.4
CVE-2021-26925

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

Fix: 1.4.11+
Fix from $1,600 2021-02-09
Fedora HIGH 8.8
CVE-2020-36152

Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.

Fix: after 1.1
Fix from $1,950 2021-02-08
Fedora MEDIUM 6.5
CVE-2020-36148

Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentatio…

Fix: after 1.1
Fix from $1,600 2021-02-08
Fedora MEDIUM 6.5
CVE-2020-36149

Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentatio…

Fix: after 1.1
Fix from $1,600 2021-02-08
Fedora MEDIUM 6.5
CVE-2020-36150

Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and access to unallocated …

Fix: after 1.1
Fix from $1,600 2021-02-08
Fedora MEDIUM 6.5
CVE-2020-36151

Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and over…

Fix: after 1.1
Fix from $1,600 2021-02-08