Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.8
CVE-2017-9105

An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences.…

Fix: 1.5.2+
Fix from $1,950 2020-06-18
Fedora HIGH 7.5
CVE-2017-9106

An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pattern for formatting integers is to sprintf into …

Fix: 1.5.2+
Fix from $1,950 2020-06-18
Fedora HIGH 7.5
CVE-2017-9107

An issue was discovered in adns before 1.5.2. It overruns reading a buffer if a domain ends with backslash. If the query domain ended with \, and adn…

Fix: 1.5.2+
Fix from $1,950 2020-06-18
Fedora HIGH 7.5
CVE-2017-9108

An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as s…

Fix: 1.5.2+
Fix from $1,950 2020-06-18
Fedora HIGH 7.2
CVE-2020-14295EPSS 86%

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution …

No fix yet
Fix from $1,950 2020-06-17
Fedora MEDIUM 5.5
CVE-2020-13999

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF …

Fix: after 1.0.12
Fix from $1,600 2020-06-15
Fedora HIGH 7.5
CVE-2020-0181

In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial o…

Fix: 0.6.22_p20201105+
Fix from $1,950 2020-06-11
Fedora HIGH 8.8
CVE-2020-2026

A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata ru…

Fix: 1.10.5 / 1.11.1+
Fix from $1,950 2020-06-10
Fedora MEDIUM 6.1
CVE-2020-13964

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username templat…

Fix: 1.3.12 / 1.4.5+
Fix from $1,600 2020-06-09
Fedora HIGH 7.5
CVE-2020-13962

Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial…

Fix: 5.12.9+
Fix from $1,950 2020-06-09
Fedora HIGH 7.5
CVE-2020-13625

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the f…

Fix: 6.1.6+
Fix from $1,950 2020-06-08
Fedora MEDIUM 6.5
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, …

Fix: 6.4.4+
Fix from $1,600 2020-06-08
Fedora MEDIUM 5.3
CVE-2020-12802

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not t…

Fix: 6.4.4+
Fix from $1,600 2020-06-08
Fedora MEDIUM 5.5
CVE-2020-13867

Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

Fix: after 2.1.52
Fix from $1,600 2020-06-05
Fedora HIGH 7.4
CVE-2020-13777EPSS 18%

GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication b…

Fix: 3.6.14+
Fix from $1,950 2020-06-04
Fedora MEDIUM 6.7
CVE-2020-13776

systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of r…

Fix: after 245
Fix from $1,600 2020-06-03
Fedora MEDIUM 6.5
CVE-2020-13775

ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled…

Patch available
Fix from $1,600 2020-06-02
Fedora HIGH 7.5
CVE-2020-13757

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by he…

Fix: 4.1+
Fix from $1,950 2020-06-01
Fedora MEDIUM 5.5
CVE-2020-12867

A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as th…

Fix: 1.0.30+
Fix from $1,600 2020-06-01
Fedora HIGH 7.8
CVE-2020-10936

Sympa before 6.2.56 allows privilege escalation.

Fix: 6.2.56+
Fix from $1,950 2020-05-27
Fedora MEDIUM 5.9
CVE-2020-13614

An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.

Fix: 2.17.8+
Fix from $1,600 2020-05-26
Fedora HIGH 7.4
CVE-2020-13482

EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of…

Patch available
Fix from $1,950 2020-05-25
Fedora HIGH 8.1
CVE-2020-12693

Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an A…

Fix: 19.05.7 / 20.02.3+
Fix from $1,950 2020-05-21
Fedora MEDIUM 6.8
CVE-2020-11078

In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body,…

Fix: 0.18.0+
Fix from $1,600 2020-05-20
Fedora HIGH 7.7
CVE-2020-10725

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application ru…

Fix: after 19.11
Fix from $1,950 2020-05-20
Fedora MEDIUM 6.5
CVE-2020-13231

In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.

Fix: 1.2.11+
Fix from $1,600 2020-05-20
Fedora HIGH 7.5
CVE-2020-10995

PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has b…

Fix: after 4.3.0
Fix from $1,950 2020-05-19
Fedora HIGH 7.5
CVE-2020-12244

An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not p…

Fix: after 4.3.0
Fix from $1,950 2020-05-19
Fedora CRITICAL 9.8
CVE-2020-12823

OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate…

Patch available
Fix from $2,300 2020-05-12
Fedora HIGH 7.8
CVE-2020-11865

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.

Fix: after 1.0.11
Fix from $1,950 2020-05-11