Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.8
CVE-2019-15151

AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

Patch available
Fix from $2,300 2019-08-18
Fedora MEDIUM 5.9
CVE-2019-13377

The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable…

Fix: after 2.8
Fix from $1,600 2019-08-15
Fedora HIGH 7.8
CVE-2019-14934

An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc fail…

Fix: 0.18+
Fix from $1,950 2019-08-11
Fedora HIGH 7.8
CVE-2019-14745

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's poss…

Fix: 3.7.0+
Fix from $1,950 2019-08-07
Fedora HIGH 8.8
CVE-2019-14732

AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.

No fix yet
Fix from $1,950 2019-08-07
Fedora HIGH 8.8
CVE-2019-14733

AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.

No fix yet
Fix from $1,950 2019-08-07
Fedora HIGH 8.8
CVE-2019-14734

AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

No fix yet
Fix from $1,950 2019-08-07
Fedora HIGH 8.8
CVE-2019-14690

AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp.

No fix yet
Fix from $1,950 2019-08-06
Fedora HIGH 8.8
CVE-2019-14691

AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp.

No fix yet
Fix from $1,950 2019-08-06
Fedora HIGH 8.8
CVE-2019-14692

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

No fix yet
Fix from $1,950 2019-08-06
Fedora MEDIUM 6.5
CVE-2019-14664

In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted p…

Fix: 2.1+
Fix from $1,600 2019-08-05
Fedora CRITICAL 9.8
CVE-2019-14532

An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using …

No fix yet
Fix from $2,300 2019-08-02
Fedora CRITICAL 9.1
CVE-2019-14463

An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS c…

Fix: 3.0.7 / 3.1.5+
Fix from $2,300 2019-07-31
Fedora CRITICAL 9.1
CVE-2019-14462

An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case,…

Fix: 3.0.7 / 3.1.5+
Fix from $2,300 2019-07-31
Fedora HIGH 7.8
CVE-2019-14267EPSS 7%

PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.

No fix yet
Fix from $1,950 2019-07-29
Fedora CRITICAL 9.8
CVE-2019-1010228EPSS 8%

OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component…

Fix: after 3.6.3
Fix from $2,300 2019-07-22
Fedora CRITICAL 9.8
CVE-2019-12815EPSS 58%

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authenti…

Fix: 2.2+
Fix from $2,300 2019-07-19
Fedora CRITICAL 9.8
CVE-2019-1010238EPSS 6%

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The comp…

Patch available
Fix from $2,300 2019-07-19
Fedora HIGH 7.5
CVE-2019-1010142

scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUS…

Patch available
Fix from $1,950 2019-07-19
Fedora MEDIUM 6.5
CVE-2019-1010065

The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237.…

Fix: after 4.6.0
Fix from $1,600 2019-07-18
Fedora MEDIUM 6.5
CVE-2019-13626

SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPC…

Fix: after 2.0.9
Fix from $1,600 2019-07-17
Fedora HIGH 7.5
CVE-2019-10190

A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass …

Fix: 4.1.0+
Fix from $1,950 2019-07-16
Fedora HIGH 7.5
CVE-2019-10191

A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains…

Fix: 4.1.0+
Fix from $1,950 2019-07-16
Fedora HIGH 7.8
CVE-2019-1010057

nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. Th…

Fix: after 1.6.16
Fix from $1,950 2019-07-16
Fedora MEDIUM 5.5
CVE-2019-1010301

jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vecto…

Patch available
Fix from $1,600 2019-07-15
Fedora MEDIUM 5.5
CVE-2019-1010302

jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vect…

No fix yet
Fix from $1,600 2019-07-15
Fedora MEDIUM 5.5
CVE-2019-1010305

libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmsp…

Patch available
Fix from $1,600 2019-07-15
Fedora MEDIUM 5.5
CVE-2019-1010315

WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tr…

Fix: after 5.1.0
Fix from $1,600 2019-07-11
Fedora MEDIUM 5.5
CVE-2019-1010317

WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The…

Fix: after 5.1.0
Fix from $1,600 2019-07-11
Fedora MEDIUM 5.5
CVE-2019-1010319

WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The…

Fix: after 5.1.0
Fix from $1,600 2019-07-11