Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.6
CVE-2020-15121

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open …

Fix: 4.5.0+
Fix from $2,300 2020-07-20
Fedora MEDIUM 6.1
CVE-2020-15803EPSS 32%

Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

Fix: after 5.0.1
Fix from $1,600 2020-07-17
Fedora MEDIUM 6.5
CVE-2020-15117

In Synergy before version 1.12.0, a Synergy server can be crashed by receiving a kMsgHelloBack packet with a client name length set to 0xffffffff (42…

Fix: 1.12.0+
Fix from $1,600 2020-07-15
Fedora MEDIUM 6.5
CVE-2020-14619

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.20 and prior. Eas…

Fix: after 8.0.20
Fix from $1,600 2020-07-15
Fedora MEDIUM 5.3
CVE-2020-14562EPSS 5%

Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Eas…

Fix: after 11.50.2
Fix from $1,600 2020-07-15
Fedora CRITICAL 10.0
CVE-2020-13753

The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NE…

Fix: 2.28.3+
Fix from $2,300 2020-07-14
Fedora HIGH 7.5
CVE-2020-10745

A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows…

Fix: 4.10.17 / 4.11.11+
Fix from $1,950 2020-07-07
Fedora HIGH 7.5
CVE-2020-14303

A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP…

Fix: 4.10.17 / 4.11.11+
Fix from $1,950 2020-07-06
Fedora HIGH 7.5
CVE-2020-15503

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_util…

Fix: after 0.19.5
Fix from $1,950 2020-07-02
Fedora MEDIUM 6.5
CVE-2020-5238

The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a ma…

Fix: 0.29.0.gfm.1+
Fix from $1,600 2020-07-01
Fedora HIGH 7.5
CVE-2020-14058

An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate …

Fix: 4.12 / 5.0.3+
Fix from $1,950 2020-06-30
Fedora HIGH 8.8
CVE-2020-15049EPSS 6%

An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can s…

Fix: 4.12 / 5.0.3+
Fix from $1,950 2020-06-30
Fedora HIGH 7.8
CVE-2020-15396

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local att…

Fix: after 7.0.2
Fix from $1,950 2020-06-30
Fedora HIGH 7.8
CVE-2020-15395

In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an o…

No fix yet
Fix from $1,950 2020-06-30
Fedora MEDIUM 5.9
CVE-2020-14002

PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle atta…

Fix: after 0.73
Fix from $1,600 2020-06-29
Fedora MEDIUM 5.5
CVE-2020-15304

An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in…

Fix: 2.5.2+
Fix from $1,600 2020-06-26
Fedora MEDIUM 5.5
CVE-2020-15305

An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmI…

Fix: 2.5.2+
Fix from $1,600 2020-06-26
Fedora MEDIUM 5.5
CVE-2020-15306

An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in Il…

Fix: 2.5.2+
Fix from $1,600 2020-06-26
Fedora HIGH 7.5
CVE-2020-4031

In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks…

Fix: 2.1.2+
Fix from $1,950 2020-06-22
Fedora MEDIUM 6.5
CVE-2020-4030

In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. T…

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Fedora MEDIUM 6.5
CVE-2020-4033

In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are a…

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Fedora MEDIUM 6.5
CVE-2020-11096

In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with …

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Fedora MEDIUM 6.5
CVE-2020-11098

In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enable…

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Fedora MEDIUM 6.5
CVE-2020-11099

In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead …

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Fedora MEDIUM 5.4
CVE-2020-11097

In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the stati…

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Fedora MEDIUM 5.4
CVE-2020-11095

In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the stati…

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Fedora HIGH 7.5
CVE-2020-14929

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less s…

Fix: 2.23+
Fix from $1,950 2020-06-19
Fedora CRITICAL 9.8
CVE-2017-9103

An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised sta…

Fix: 1.5.2+
Fix from $2,300 2020-06-18
Fedora CRITICAL 9.8
CVE-2017-9104

An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.

Fix: 1.5.2+
Fix from $2,300 2020-06-18
Fedora CRITICAL 9.8
CVE-2017-9109

An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fix…

Fix: 1.5.2+
Fix from $2,300 2020-06-18