Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.5
CVE-2020-11743

An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant…

Fix: after 4.13.0
Fix from $1,600 2020-04-14
Fedora HIGH 7.5
CVE-2013-7488

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

Fix: after 0.27
Fix from $1,950 2020-04-07
Fedora HIGH 8.1
CVE-2020-6096EPSS 5%

An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets…

Fix: after 2.31
Fix from $1,950 2020-04-01
Fedora MEDIUM 6.1
CVE-2020-6802

In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.

Fix: 3.1.1+
Fix from $1,600 2020-03-24
Fedora MEDIUM 6.1
CVE-2020-6816

In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=…

Fix: 3.1.2+
Fix from $1,600 2020-03-24
Fedora MEDIUM 5.9
CVE-2020-10941

Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.

Fix: 2.16.5 / 3.1.0+
Fix from $1,600 2020-03-24
Fedora CRITICAL 9.8
CVE-2020-1747EPSS 5%

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes …

Fix: 5.3.1+
Fix from $2,300 2020-03-24
Fedora HIGH 8.0
CVE-2020-10804

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/class…

Fix: 4.9.5 / 5.0.2+
Fix from $1,950 2020-03-22
Fedora HIGH 7.5
CVE-2019-14855

A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness…

Fix: 2.2.18+
Fix from $1,950 2020-03-20
Fedora HIGH 7.5
CVE-2020-10675

The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.

Fix: 1.0.0+
Fix from $1,950 2020-03-19
Fedora HIGH 7.5
CVE-2020-6582

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a …

No fix yet
Fix from $1,950 2020-03-16
Fedora HIGH 7.3
CVE-2020-6581

Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \…

No fix yet
Fix from $1,950 2020-03-16
Fedora CRITICAL 9.8
CVE-2020-10108

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the fir…

Fix: after 19.10.0
Fix from $2,300 2020-03-12
Fedora CRITICAL 9.8
CVE-2020-10109

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header…

Fix: after 19.10.0
Fix from $2,300 2020-03-12
Fedora MEDIUM 6.1
CVE-2020-9440

A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script insid…

Fix: after 5.5.7.5
Fix from $1,600 2020-03-10
Fedora MEDIUM 6.1
CVE-2020-9281

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web sc…

Fix: 4.14 / 8.7.12+
Fix from $1,600 2020-03-07
Fedora CRITICAL 9.8
CVE-2020-10188EPSS 74%

utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a bu…

Fix: after 4.23.3m
Fix from $2,300 2020-03-06
Fedora HIGH 7.0
CVE-2020-10174

init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/times…

Fix: 20.03+
Fix from $1,950 2020-03-05
Fedora MEDIUM 5.5
CVE-2020-10029

The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double func…

Fix: 2.32.0+
Fix from $1,600 2020-03-04
Fedora CRITICAL 9.8
CVE-2020-10018

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-fre…

Fix: 2.28.0+
Fix from $2,300 2020-03-02
Fedora CRITICAL 9.1
CVE-2020-7043

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname compa…

Fix: 1.12.0+
Fix from $2,300 2020-02-27
Fedora MEDIUM 5.3
CVE-2020-7041

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_chec…

Fix: 1.12.0+
Fix from $1,600 2020-02-27
Fedora MEDIUM 5.3
CVE-2020-7042

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname…

Fix: 1.12.0+
Fix from $1,600 2020-02-27
Fedora HIGH 7.5
CVE-2020-9369

Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications…

Fix: after 6.2.52
Fix from $1,950 2020-02-24
Fedora HIGH 7.5
CVE-2020-9365EPSS 7%

An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

Patch available
Fix from $1,950 2020-02-24
Fedora CRITICAL 9.8
CVE-2019-18182

pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsi…

Fix: 5.2+
Fix from $2,300 2020-02-24
Fedora CRITICAL 9.8
CVE-2019-18183

pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsig…

Fix: 5.2+
Fix from $2,300 2020-02-24
Fedora HIGH 7.8
CVE-2019-20044

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved u…

Fix: 5.8 / 6.2.5+
Fix from $1,950 2020-02-24
Fedora HIGH 8.8
CVE-2020-8813EPSS 74%

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has …

No fix yet
Fix from $1,950 2020-02-22
Fedora CRITICAL 9.8
CVE-2020-6061EPSS 5%

An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST …

No fix yet
Fix from $2,300 2020-02-19