Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2019-20176

In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.

Patch available
Fix from $1,950 2019-12-31
Fedora HIGH 7.5
CVE-2012-5645

A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a …

Fix: 2.3.4+
Fix from $1,950 2019-12-30
Fedora MEDIUM 5.5
CVE-2019-20093

The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer deref…

No fix yet
Fix from $1,600 2019-12-30
Fedora MEDIUM 5.5
CVE-2019-20051

A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which…

No fix yet
Fix from $1,600 2019-12-27
Fedora MEDIUM 5.5
CVE-2019-20021

A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.

No fix yet
Fix from $1,600 2019-12-27
Sssd HIGH 8.8
CVE-2012-3462

A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event tha…

Patch available
Fix from $1,950 2019-12-26
Fedora HIGH 7.8
CVE-2019-19917

Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

No fix yet
Fix from $1,950 2019-12-20
Fedora HIGH 7.8
CVE-2019-19918

Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

No fix yet
Fix from $1,950 2019-12-20
Fedora HIGH 7.5
CVE-2019-3992

ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's config…

Fix: after 3.1.4-57bea22
Fix from $1,950 2019-12-17
Fedora HIGH 7.5
CVE-2019-3993EPSS 46%

ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password …

Fix: after 3.1.4-57bea22
Fix from $1,950 2019-12-17
Fedora HIGH 7.5
CVE-2019-3994

ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash th…

Fix: after 3.1.4-57bea22
Fix from $1,950 2019-12-17
Fedora HIGH 7.5
CVE-2019-3995EPSS 29%

ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker ca…

Fix: after 3.1.4-57bea22
Fix from $1,950 2019-12-17
Fedora MEDIUM 6.5
CVE-2019-3996EPSS 6%

ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.

Fix: after 3.1.4-57bea22
Fix from $1,600 2019-12-17
Fedora MEDIUM 5.5
CVE-2019-19797

read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.

No fix yet
Fix from $1,600 2019-12-15
Fedora MEDIUM 5.3
CVE-2019-19722

In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL …

Fix: 2.3.9.2+
Fix from $1,600 2019-12-13
Fedora HIGH 7.8
CVE-2019-19785

ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.

No fix yet
Fix from $1,950 2019-12-13
Fedora HIGH 7.8
CVE-2019-19786

ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.

No fix yet
Fix from $1,950 2019-12-13
Fedora HIGH 7.8
CVE-2019-19787

ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.

No fix yet
Fix from $1,950 2019-12-13
Fedora MEDIUM 6.5
CVE-2019-16777

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be…

Fix: 6.13.4+
Fix from $1,600 2019-12-13
Fedora HIGH 8.1
CVE-2019-16776

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node…

Fix: 6.13.3+
Fix from $1,950 2019-12-13
Fedora MEDIUM 5.5
CVE-2019-19746

make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow typ…

No fix yet
Fix from $1,600 2019-12-12
Fedora HIGH 7.5
CVE-2017-18640EPSS 27%

The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.

Fix: 1.26+
Fix from $1,950 2019-12-12
Fedora HIGH 8.8
CVE-2019-19578

An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables,…

Fix: after 4.12.1
Fix from $1,950 2019-12-11
Fedora HIGH 7.5
CVE-2019-19583

An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry c…

Fix: after 4.12.1
Fix from $1,950 2019-12-11
Fedora HIGH 7.2
CVE-2019-19577

An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by trigger…

Fix: after 4.12.1
Fix from $1,950 2019-12-11
Fedora MEDIUM 6.6
CVE-2019-19580

An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable pr…

Fix: after 4.12.1
Fix from $1,600 2019-12-11
Fedora MEDIUM 6.5
CVE-2019-19581

An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain …

Fix: after 4.12.1
Fix from $1,600 2019-12-11
Fedora MEDIUM 6.5
CVE-2019-19582

An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration …

Fix: after 4.12.1
Fix from $1,600 2019-12-11
Fedora MEDIUM 5.4
CVE-2019-14870

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation mode…

Fix: 4.9.17 / 4.10.11+
Fix from $1,600 2019-12-10
Fedora MEDIUM 5.3
CVE-2019-14861

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe pro…

Fix: 4.9.17 / 4.10.11+
Fix from $1,600 2019-12-10