Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.4
CVE-2019-12098

In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This iss…

Fix: 7.6.0+
Fix from $1,950 2019-05-15
Fedora HIGH 7.5
CVE-2019-8936EPSS 6%

NTP through 4.2.8p12 has a NULL Pointer Dereference.

Fix: 4.2.8 / 9.2+
Fix from $1,950 2019-05-15
Fedora HIGH 8.8
CVE-2019-11328

An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit thi…

Fix: 3.2.0+
Fix from $1,950 2019-05-14
Fedora HIGH 7.5
CVE-2019-11494

In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH com…

Fix: after 2.3.5.2
Fix from $1,950 2019-05-08
Fedora HIGH 7.5
CVE-2019-11499

In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel wit…

Fix: after 2.3.5.2
Fix from $1,950 2019-05-08
Fedora HIGH 8.1
CVE-2019-7443

KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain typ…

Fix: 5.55.0+
Fix from $1,950 2019-05-07
Fedora HIGH 7.8
CVE-2019-3843

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient s…

Fix: 242+
Fix from $1,950 2019-04-26
Fedora MEDIUM 6.5
CVE-2019-11474

coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an X…

Patch available
Fix from $1,600 2019-04-23
Fedora HIGH 7.5
CVE-2019-5427

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity…

Fix: 0.9.5.4+
Fix from $1,950 2019-04-22
Fedora HIGH 7.5
CVE-2019-11412

An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode…

Patch available
Fix from $1,950 2019-04-22
Fedora CRITICAL 9.8
CVE-2019-11234EPSS 8%

FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.

Fix: 3.0.19+
Fix from $2,300 2019-04-22
Fedora CRITICAL 9.8
CVE-2019-11235

FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is…

Patch available
Fix from $2,300 2019-04-22
Fedora MEDIUM 6.5
CVE-2019-11372

An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a …

Patch available
Fix from $1,600 2019-04-20
Fedora MEDIUM 6.5
CVE-2019-11373

An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.

Patch available
Fix from $1,600 2019-04-20
Fedora HIGH 8.1
CVE-2019-9498

The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not va…

Fix: after 11.1
Fix from $1,950 2019-04-17
Fedora HIGH 8.1
CVE-2019-9499

The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do n…

Fix: after 11.1
Fix from $1,950 2019-04-17
Fedora HIGH 8.1
CVE-2019-9497

The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. Thi…

Fix: after 2.7
Fix from $1,950 2019-04-17
Fedora HIGH 7.5
CVE-2019-9496

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE conf…

Fix: after 2.7
Fix from $1,950 2019-04-17
Fedora MEDIUM 5.9
CVE-2019-9494

The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cach…

Fix: 1.2.3-8087+
Fix from $1,600 2019-04-17
Fedora MEDIUM 5.9
CVE-2019-11065

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are u…

Fix: after 5.3.1
Fix from $1,600 2019-04-10
Fedora MEDIUM 5.5
CVE-2019-9133

When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer unde…

Fix: after 2018.12.24.14
Fix from $1,600 2019-04-09
Fedora MEDIUM 6.1
CVE-2019-3870

A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files …

Fix: 2.3.6-1720 / 4.9.6+
Fix from $1,600 2019-04-09
Fedora MEDIUM 6.1
CVE-2019-9844

simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.

Fix: 0.4.4+
Fix from $1,600 2019-04-09
Fedora MEDIUM 6.5
CVE-2019-11026

FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.

No fix yet
Fix from $1,600 2019-04-08
Fedora HIGH 8.6
CVE-2019-10906

In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

Fix: 2.10.1+
Fix from $1,950 2019-04-07
Fedora HIGH 7.5
CVE-2019-3836

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can b…

Fix: 3.6.7+
Fix from $1,950 2019-04-01
Fedora CRITICAL 9.8
CVE-2019-0160

Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service v…

Mitigation only
Fix from $2,300 2019-03-27
Fedora HIGH 7.5
CVE-2018-12545EPSS 5%

In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs fra…

Patch available
Fix from $1,950 2019-03-27
Fedora HIGH 7.5
CVE-2019-3829EPSS 59%

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification…

Fix: 3.6.7+
Fix from $1,950 2019-03-27
Fedora HIGH 7.5
CVE-2019-3804

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthen…

Fix: 184+
Fix from $1,950 2019-03-26