Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.5
CVE-2020-36241

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extra…

Fix: after 0.2.4
Fix from $1,600 2021-02-05
Fedora MEDIUM 5.3
CVE-2020-28493

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its u…

Fix: 2.11.3+
Fix from $1,600 2021-02-01
Fedora CRITICAL 9.8
CVE-2021-3325

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option)…

Patch available
Fix from $2,300 2021-01-27
Fedora MEDIUM 5.5
CVE-2021-3272

jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number …

No fix yet
Fix from $1,600 2021-01-27
Fedora HIGH 7.8
CVE-2021-3156 KEVEPSS 99%

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo…

Fix: 1.8.32 / 1.9.5+
Fix from $1,950 2021-01-26
Fedora MEDIUM 5.5
CVE-2021-3308

An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocati…

Fix: after 4.14.1
Fix from $1,600 2021-01-26
Fedora MEDIUM 5.9
CVE-2020-25687EPSS 87%

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validate…

Fix: 2.83+
Fix from $1,600 2021-01-20
Fedora HIGH 8.1
CVE-2020-25681EPSS 81%

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSS…

Fix: 2.83+
Fix from $1,950 2021-01-20
Fedora HIGH 8.1
CVE-2020-25682EPSS 71%

A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before vali…

Fix: 2.83+
Fix from $1,950 2021-01-20
Fedora MEDIUM 5.9
CVE-2020-25683EPSS 86%

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validate…

Fix: 2.83+
Fix from $1,600 2021-01-20
Fedora HIGH 7.8
CVE-2020-14409

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_co…

Fix: after 2.0.20
Fix from $1,950 2021-01-19
Fedora HIGH 7.5
CVE-2020-35733

An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root…

Fix: 23.2.2+
Fix from $1,950 2021-01-15
Fedora HIGH 7.2
CVE-2020-26262

Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay p…

Fix: 4.5.2+
Fix from $1,950 2021-01-13
Fedora HIGH 7.5
CVE-2021-1723

ASP.NET Core and Visual Studio Denial of Service Vulnerability

Fix: after 16.8
Fix from $1,950 2021-01-12
Fedora HIGH 7.8
CVE-2021-23240

selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacin…

Fix: 1.8.32 / 1.9.5+
Fix from $1,950 2021-01-12
Fedora HIGH 8.8
CVE-2020-35701

An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execu…

Fix: after 1.2.16
Fix from $1,950 2021-01-11
Fedora MEDIUM 5.5
CVE-2020-27842

There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg coul…

Patch available
Fix from $1,600 2021-01-05
Fedora MEDIUM 5.5
CVE-2020-27843

A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encodin…

Fix: 2.4.0+
Fix from $1,600 2021-01-05
Fedora MEDIUM 5.5
CVE-2020-27845

There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conver…

Fix: 2.4.0+
Fix from $1,600 2021-01-05
Fedora MEDIUM 5.5
CVE-2020-27841

There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by t…

Fix: 2.4.0+
Fix from $1,600 2021-01-05
Fedora MEDIUM 5.9
CVE-2019-25013

The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, …

Fix: after 2.32
Fix from $1,600 2021-01-04
Fedora MEDIUM 5.5
CVE-2020-35496

There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be proc…

Fix: 2.34+
Fix from $1,600 2021-01-04
Fedora MEDIUM 6.1
CVE-2020-35494

There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage…

Fix: 2.34+
Fix from $1,600 2021-01-04
Fedora MEDIUM 5.5
CVE-2020-35495

There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a nu…

Fix: 2.34+
Fix from $1,600 2021-01-04
Fedora MEDIUM 5.5
CVE-2020-35493

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overfl…

Fix: 2.34+
Fix from $1,600 2021-01-04
Fedora MEDIUM 6.1
CVE-2020-35730 KEVEPSS 33%

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-ma…

Fix: 1.2.13 / 1.3.16+
Fix from $1,600 2020-12-28
Fedora HIGH 7.5
CVE-2020-35376

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() func…

No fix yet
Fix from $1,950 2020-12-26
Fedora HIGH 7.5
CVE-2020-35679

smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messag…

Fix: 6.8.0+
Fix from $1,950 2020-12-24
Fedora HIGH 7.5
CVE-2020-35680

smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer derefer…

Fix: 6.8.0+
Fix from $1,950 2020-12-24
Fedora MEDIUM 6.1
CVE-2020-35474

In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-lege…

Fix: 1.35.1+
Fix from $1,600 2020-12-18