Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.8
CVE-2019-20477EPSS 5%

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a …

Fix: after 5.1.2
Fix from $2,300 2020-02-19
Fedora CRITICAL 9.8
CVE-2020-8518EPSS 72%

Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

No fix yet
Fix from $2,300 2020-02-17
Fedora HIGH 7.5
CVE-2019-20454

An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2020-02-14
Fedora CRITICAL 9.8
CVE-2020-8955

irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and ap…

Fix: after 2.7
Fix from $2,300 2020-02-12
Fedora HIGH 7.5
CVE-2020-7046EPSS 51%

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the u…

Fix: 2.3.9.3+
Fix from $1,950 2020-02-12
Fedora MEDIUM 5.3
CVE-2020-7957

The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet an…

Fix: 2.3.9.3+
Fix from $1,600 2020-02-12
Fedora HIGH 7.5
CVE-2018-14553

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific functi…

Fix: after 2.2.5
Fix from $1,950 2020-02-11
Fedora HIGH 7.5
CVE-2013-4572

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache sessio…

Fix: 1.19.9 / 1.20.8+
Fix from $1,950 2020-02-06
Fedora HIGH 7.5
CVE-2010-5304

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use thi…

Fix: 0.9.9+
Fix from $1,950 2020-02-05
Fedora HIGH 7.5
CVE-2019-12528EPSS 10%

An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as…

Fix: 4.10+
Fix from $1,950 2020-02-04
Fedora MEDIUM 6.5
CVE-2019-20446

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processi…

Fix: 2.40.21 / 2.42.8+
Fix from $1,600 2020-02-02
Fedora HIGH 7.5
CVE-2011-4088

ABRT might allow attackers to obtain sensitive information from crash reports.

Mitigation only
Fix from $1,950 2020-01-31
Fedora MEDIUM 5.9
CVE-2013-0294

packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attacke…

Fix: 2.1+
Fix from $1,600 2020-01-28
Fedora HIGH 7.5
CVE-2014-2581

Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.

Fix: 1.1.1+
Fix from $1,950 2020-01-28
Fedora HIGH 7.5
CVE-2020-7238

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line)…

No fix yet
Fix from $1,950 2020-01-27
Fedora HIGH 7.5
CVE-2015-9541

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue …

Fix: 5.12.8+
Fix from $1,950 2020-01-24
Fedora MEDIUM 6.5
CVE-2015-5745

Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service …

Fix: 2.4.0+
Fix from $1,600 2020-01-23
Fedora MEDIUM 6.5
CVE-2015-5239

Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT m…

Fix: 2.1.0+
Fix from $1,600 2020-01-23
Fedora MEDIUM 6.5
CVE-2015-5278

The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash…

Fix: 2.4.0.1+
Fix from $1,600 2020-01-23
Fedora HIGH 7.5
CVE-2020-7595EPSS 8%

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

Fix: 3.0+
Fix from $1,950 2020-01-21
Fedora HIGH 7.5
CVE-2019-19886

Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the serve…

Fix: after 3.0.3
Fix from $1,950 2020-01-21
Fedora MEDIUM 6.5
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or abov…

Fix: 4.9.18 / 4.10.12+
Fix from $1,600 2020-01-21
Fedora MEDIUM 6.1
CVE-2019-19547

Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue tha…

Fix: 4.3.0+
Fix from $1,600 2020-01-13
Fedora HIGH 8.8
CVE-2020-6860

libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.

No fix yet
Fix from $1,950 2020-01-13
Fedora HIGH 7.5
CVE-2020-6851

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimen…

Patch available
Fix from $1,950 2020-01-13
Fedora MEDIUM 5.9
CVE-2020-6750

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when config…

Fix: after 2.62.4
Fix from $1,600 2020-01-09
Fedora MEDIUM 6.7
CVE-2019-5188

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cau…

Fix: after 1.45.4
Fix from $1,600 2020-01-08
Fedora HIGH 8.8
CVE-2020-5395

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

Patch available
Fix from $1,950 2020-01-03
Fedora MEDIUM 6.1
CVE-2012-4451

Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTM…

Fix: 2.0.1+
Fix from $1,600 2020-01-03
Fedora HIGH 7.8
CVE-2013-4161

gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security iss…

Mitigation only
Fix from $1,950 2019-12-31