Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.8
CVE-2019-12527EPSS 49%

An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store…

Fix: after 4.7
Fix from $1,950 2019-07-11
Fedora MEDIUM 6.5
CVE-2019-13225

A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a craft…

Patch available
Fix from $1,600 2019-07-10
Fedora HIGH 7.8
CVE-2019-13313

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the comm…

Patch available
Fix from $1,950 2019-07-05
Fedora MEDIUM 5.5
CVE-2019-13286

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for examp…

No fix yet
Fix from $1,600 2019-07-04
Fedora HIGH 7.8
CVE-2019-13281

In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, fo…

No fix yet
Fix from $1,950 2019-07-04
Fedora HIGH 7.8
CVE-2019-13282

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. …

No fix yet
Fix from $1,950 2019-07-04
Fedora HIGH 7.8
CVE-2019-13283

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure th…

No fix yet
Fix from $1,950 2019-07-04
Fedora HIGH 7.0
CVE-2019-13226

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to tem…

Fix: 1.1.3+
Fix from $1,950 2019-07-04
Fedora MEDIUM 5.3
CVE-2019-13118EPSS 5%

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combin…

Patch available
Fix from $1,600 2019-07-01
Fedora MEDIUM 6.5
CVE-2019-13109

An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage:…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Fedora MEDIUM 6.5
CVE-2019-13110

A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSE…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Fedora MEDIUM 6.5
CVE-2019-13112

A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Fedora MEDIUM 6.5
CVE-2019-13113

Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image fil…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Fedora MEDIUM 6.5
CVE-2019-13114

http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a c…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Fedora MEDIUM 5.5
CVE-2019-13111

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Fedora MEDIUM 6.5
CVE-2019-13108

An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage:…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Fedora CRITICAL 9.8
CVE-2019-13107

Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c

Fix: 1.5.16+
Fix from $2,300 2019-06-30
Fedora HIGH 7.5
CVE-2019-13050

Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyse…

Fix: after 5.1.0
Fix from $1,950 2019-06-29
Fedora HIGH 7.8
CVE-2019-12957

In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the c…

No fix yet
Fix from $1,950 2019-06-25
Fedora HIGH 7.8
CVE-2019-12802

In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial…

Fix: after 3.5.1
Fix from $1,950 2019-06-13
Fedora MEDIUM 6.1
CVE-2019-12387

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CR…

Fix: 19.2.1+
Fix from $1,600 2019-06-10
Fedora CRITICAL 9.8
CVE-2019-11356EPSS 8%

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafte…

Fix: after 3.0.9
Fix from $2,300 2019-06-03
Fedora MEDIUM 5.6
CVE-2019-11091

Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an …

Mitigation only
Fix from $1,600 2019-05-30
Fedora MEDIUM 5.9
CVE-2018-12130

Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated…

No fix yet
Fix from $1,600 2019-05-30
Fedora MEDIUM 5.6
CVE-2018-12126

Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticat…

No fix yet
Fix from $1,600 2019-05-30
Fedora MEDIUM 5.6
CVE-2018-12127

Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated use…

No fix yet
Fix from $1,600 2019-05-30
Fedora HIGH 7.8
CVE-2019-5436EPSS 50%

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Fix: after 7.64.1
Fix from $1,950 2019-05-28
Fedora HIGH 7.0
CVE-2019-10143

It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has con…

Fix: after 3.0.19
Fix from $1,950 2019-05-24
Fedora MEDIUM 6.5
CVE-2019-12216

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There…

No fix yet
Fix from $1,600 2019-05-20
Fedora MEDIUM 6.5
CVE-2019-12221

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There…

No fix yet
Fix from $1,600 2019-05-20