Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.8
CVE-2020-11866

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.

Fix: after 1.0.11
Fix from $1,950 2020-05-11
Fedora MEDIUM 5.5
CVE-2020-11863

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).

Fix: after 1.0.11
Fix from $1,600 2020-05-11
Fedora MEDIUM 5.5
CVE-2020-11864

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).

Fix: after 1.0.11
Fix from $1,600 2020-05-11
Fedora HIGH 7.5
CVE-2020-12783

Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/aut…

Fix: after 4.93
Fix from $1,950 2020-05-11
Fedora HIGH 7.8
CVE-2020-12762

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Fix: 0.15-20200726+
Fix from $1,950 2020-05-09
Fedora CRITICAL 9.1
CVE-2020-12740

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ip…

Fix: after 4.3.2
Fix from $2,300 2020-05-08
Fedora HIGH 7.5
CVE-2020-10704

A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Doma…

Fix: 4.10.15 / 4.11.8+
Fix from $1,950 2020-05-06
Fedora MEDIUM 6.1
CVE-2020-12666

macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.

Fix: 1.3.7+
Fix from $1,600 2020-05-05
Fedora CRITICAL 9.3
CVE-2020-11035

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and un…

Fix: 9.4.6+
Fix from $2,300 2020-05-05
Fedora HIGH 7.2
CVE-2020-11033

In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying…

Fix: 9.4.6+
Fix from $1,950 2020-05-05
Fedora MEDIUM 5.3
CVE-2020-10700

A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious …

Fix: 4.10.15 / 4.11.8+
Fix from $1,600 2020-05-04
Fedora HIGH 7.0
CVE-2020-12050

SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any use…

Mitigation only
Fix from $1,950 2020-04-30
Fedora CRITICAL 9.8
CVE-2019-18823

HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authent…

Fix: after 8.9.4
Fix from $2,300 2020-04-27
Fedora CRITICAL 9.8
CVE-2019-20790

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where th…

Fix: after 1.3.2
Fix from $2,300 2020-04-27
Fedora MEDIUM 5.3
CVE-2020-12272

OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an …

Fix: after 1.3.2
Fix from $1,600 2020-04-27
Fedora MEDIUM 6.5
CVE-2020-1983

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

Fix: after 4.2.0
Fix from $1,600 2020-04-22
Fedora HIGH 7.5
CVE-2020-12066

CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.

Fix: 0.7.5+
Fix from $1,950 2020-04-22
Fedora HIGH 7.8
CVE-2020-0081

In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2020-04-17
Fedora MEDIUM 5.0
CVE-2020-2934

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.19 and prior and…

Fix: after 8.0.19
Fix from $1,600 2020-04-15
Fedora MEDIUM 5.5
CVE-2020-11758

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11759

An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCou…

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11760

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11761

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refi…

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11762

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when h…

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11763

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11764

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11765

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Clas…

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora HIGH 8.8
CVE-2020-11741

An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about othe…

Fix: after 4.13.0
Fix from $1,950 2020-04-14
Fedora HIGH 7.8
CVE-2020-11739

An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing me…

Fix: after 4.13.0
Fix from $1,950 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11742

An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of bad continuation handling in GNTTABOP_…

Fix: after 4.13.0
Fix from $1,600 2020-04-14