Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.8
CVE-2019-19647

radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitr…

Fix: after 4.0.0
Fix from $1,950 2019-12-09
Fedora HIGH 7.8
CVE-2019-19648

In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO…

No fix yet
Fix from $1,950 2019-12-09
Fedora HIGH 7.8
CVE-2012-1615

A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.

Patch available
Fix from $1,950 2019-12-06
Fedora MEDIUM 5.5
CVE-2012-1105

An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Serv…

Patch available
Fix from $1,600 2019-12-05
Fedora MEDIUM 6.8
CVE-2019-19579

An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…

Fix: after 4.12.1
Fix from $1,600 2019-12-04
Fedora HIGH 7.5
CVE-2013-4410

ReviewBoard: has an access-control problem in REST API

Fix: 1.6.19 / 1.7.15+
Fix from $1,950 2019-12-02
Fedora HIGH 7.8
CVE-2012-4480

mom creates world-writable pid files in /var/run

Fix: 0.3.0-1+
Fix from $1,950 2019-12-02
Fedora CRITICAL 9.8
CVE-2019-18609

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corrupt…

Fix: 0.10.0+
Fix from $2,300 2019-12-01
Fedora MEDIUM 5.5
CVE-2019-19451

When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loo…

Fix: 2019-11-27+
Fix from $1,600 2019-11-29
Fedora HIGH 7.8
CVE-2019-14812

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls,…

Fix: 9.50+
Fix from $1,950 2019-11-27
Fedora HIGH 8.8
CVE-2019-14867EPSS 7%

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the interna…

Fix: 4.6.7 / 4.7.4+
Fix from $1,950 2019-11-27
Fedora MEDIUM 6.5
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIP…

Fix: 4.6.7 / 4.7.4+
Fix from $1,600 2019-11-27
Fedora HIGH 7.5
CVE-2019-6477

With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without…

Fix: after 9.15.5
Fix from $1,950 2019-11-26
Fedora HIGH 7.5
CVE-2019-19270

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for su…

Fix: after 1.3.5
Fix from $1,950 2019-11-26
Fedora HIGH 7.8
CVE-2012-5617

gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation

Mitigation only
Fix from $1,950 2019-11-25
Fedora HIGH 7.5
CVE-2012-5535

gnome-system-log polkit policy allows arbitrary files on the system to be read

No fix yet
Fix from $1,950 2019-11-25
Fedora MEDIUM 6.3
CVE-2012-5630

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

Mitigation only
Fix from $1,600 2019-11-25
Fedora HIGH 7.5
CVE-2019-11287

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.1…

Fix: 1.16.7 / 1.17.4+
Fix from $1,950 2019-11-23
Fedora CRITICAL 9.8
CVE-2019-18622

An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer …

Fix: 4.9.2+
Fix from $2,300 2019-11-22
Fedora HIGH 7.5
CVE-2019-19203

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced wit…

Fix: 6.9.4+
Fix from $1,950 2019-11-21
Fedora MEDIUM 6.1
CVE-2015-2793

Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary w…

Fix: 3.20150329+
Fix from $1,600 2019-11-21
Fedora HIGH 7.5
CVE-2012-4524

xlockmore before 5.43 'dclock' security bypass vulnerability

Fix: 5.43+
Fix from $1,950 2019-11-21
Fedora HIGH 7.3
CVE-2019-18934

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answe…

Fix: after 1.9.4
Fix from $1,950 2019-11-19
Fedora CRITICAL 9.8
CVE-2019-19010

Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose i…

Fix: 2019.11.09+
Fix from $2,300 2019-11-16
Fedora HIGH 8.8
CVE-2019-14869

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged cal…

Fix: 9.50+
Fix from $1,950 2019-11-15
Fedora CRITICAL 9.8
CVE-2019-18928

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication con…

Fix: 2.5.14 / 3.0.12+
Fix from $2,300 2019-11-15
Fedora MEDIUM 6.5
CVE-2019-11135

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information discl…

Patch available
Fix from $1,600 2019-11-14
Fedora HIGH 8.6
CVE-2019-18837

An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to…

Fix: 0.10.5+
Fix from $1,950 2019-11-13
Fedora MEDIUM 5.5
CVE-2010-4177

mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clea…

Fix: 5.0r14+
Fix from $1,600 2019-11-12
Fedora MEDIUM 5.5
CVE-2019-18849

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat ap…

Fix: 1.4.18+
Fix from $1,600 2019-11-11