Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.5
CVE-2010-4178

MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console

Mitigation only
Fix from $1,600 2019-11-06
Fedora MEDIUM 6.5
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to t…

Fix: 4.9.15 / 4.10.10+
Fix from $1,600 2019-11-06
Fedora MEDIUM 5.4
CVE-2019-14833

A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password …

Fix: 4.9.15 / 4.10.10+
Fix from $1,600 2019-11-06
Fedora MEDIUM 5.9
CVE-2013-5123EPSS 8%

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perfo…

Fix: 1.5+
Fix from $1,600 2019-11-05
Fedora CRITICAL 9.8
CVE-2013-4409

An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

Fix: 1.7.15+
Fix from $2,300 2019-11-04
Fedora HIGH 7.8
CVE-2013-4251

The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.

Fix: 0.12.1+
Fix from $1,950 2019-11-04
Fedora MEDIUM 6.1
CVE-2013-1931

A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related t…

Patch available
Fix from $1,600 2019-10-31
Fedora CRITICAL 9.8
CVE-2018-21029

systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent,…

Fix: 244+
Fix from $2,300 2019-10-30
Fedora HIGH 8.1
CVE-2019-17498

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to s…

Fix: after 1.9.0
Fix from $1,950 2019-10-21
Fedora HIGH 8.8
CVE-2019-14287EPSS 64%

In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can ca…

Patch available
Fix from $1,950 2019-10-17
Fedora HIGH 7.5
CVE-2019-17592

The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regu…

Fix: 4.4.6+
Fix from $1,950 2019-10-14
Fedora CRITICAL 9.8
CVE-2019-17042

An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parse…

Patch available
Fix from $2,300 2019-10-07
Fedora MEDIUM 6.5
CVE-2019-9433

In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no addi…

Mitigation only
Fix from $1,600 2019-09-27
Fedora MEDIUM 6.5
CVE-2019-9371

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional e…

Mitigation only
Fix from $1,600 2019-09-27
Fedora HIGH 8.8
CVE-2019-9278

In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media conten…

Patch available
Fix from $1,950 2019-09-27
Fedora MEDIUM 5.3
CVE-2019-16910

Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, …

Fix: 2.0.0 / 2.7.12+
Fix from $1,600 2019-09-26
Fedora HIGH 7.5
CVE-2019-14844

A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the…

Fix: after 1.17.1
Fix from $1,950 2019-09-26
Fedora MEDIUM 5.3
CVE-2019-16738

In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.

Fix: 1.31.4 / 1.32.4+
Fix from $1,600 2019-09-26
Fedora MEDIUM 5.5
CVE-2019-16892

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed.…

Fix: 1.3.0+
Fix from $1,600 2019-09-25
Fedora MEDIUM 6.5
CVE-2019-16707

Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.

No fix yet
Fix from $1,600 2019-09-23
Fedora CRITICAL 9.8
CVE-2019-16239

process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.

Fix: 8.05+
Fix from $2,300 2019-09-17
Fedora CRITICAL 9.8
CVE-2019-14540EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-09-15
Fedora CRITICAL 9.8
CVE-2019-16335

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-09-15
Fedora MEDIUM 6.5
CVE-2019-12922EPSS 10%

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

Fix: after 4.9.0.1
Fix from $1,600 2019-09-13
Fedora HIGH 7.5
CVE-2019-16163

Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.

Fix: 6.9.3+
Fix from $1,950 2019-09-09
Fedora MEDIUM 5.5
CVE-2019-16167

sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.

Fix: 12.1.6+
Fix from $1,600 2019-09-09
Fedora HIGH 7.5
CVE-2019-16159

BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 admin…

Fix: after 2.0.5
Fix from $1,950 2019-09-09
Fedora CRITICAL 9.8
CVE-2019-10746

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or m…

Fix: 1.3.2+
Fix from $2,300 2019-08-23
Fedora HIGH 8.8
CVE-2019-2126EPSS 6%

In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote co…

Mitigation only
Fix from $1,950 2019-08-20
Fedora HIGH 7.4
CVE-2019-15237

Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.

Fix: after 1.3.9
Fix from $1,950 2019-08-20