Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.1
CVE-2019-3858EPSS 6%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker…

Fix: 1.8.1+
Fix from $2,300 2019-03-21
Fedora HIGH 8.8
CVE-2019-3855EPSS 9%

An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the serve…

Patch available
Fix from $1,950 2019-03-21
Fedora HIGH 8.8
CVE-2019-3871EPSS 13%

A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user whe…

Fix: 4.0.7 / 4.1.7+
Fix from $1,950 2019-03-21
Fedora MEDIUM 6.5
CVE-2019-9903

PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.…

No fix yet
Fix from $1,600 2019-03-21
Fedora CRITICAL 9.8
CVE-2019-9895

In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

Fix: 0.71+
Fix from $2,300 2019-03-21
Fedora CRITICAL 9.8
CVE-2019-9898

Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

Fix: 0.71+
Fix from $2,300 2019-03-21
Fedora HIGH 7.5
CVE-2019-9894

A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

Fix: 0.71+
Fix from $1,950 2019-03-21
Fedora HIGH 7.5
CVE-2019-9897

Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.

Fix: 0.71+
Fix from $1,950 2019-03-21
Fedora HIGH 7.8
CVE-2019-6778

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

Patch available
Fix from $1,950 2019-03-21
Fedora MEDIUM 5.5
CVE-2019-6501

In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.

Patch available
Fix from $1,600 2019-03-21
Fedora HIGH 7.8
CVE-2019-6116EPSS 43%

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

Patch available
Fix from $1,950 2019-03-21
Fedora HIGH 7.5
CVE-2019-5885

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and…

Fix: 0.34.0.1+
Fix from $1,950 2019-03-21
Fedora CRITICAL 9.1
CVE-2019-3859EPSS 6%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote att…

Fix: 1.8.1+
Fix from $2,300 2019-03-21
Fedora CRITICAL 9.1
CVE-2019-3862EPSS 8%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no paylo…

Fix: 1.8.1+
Fix from $2,300 2019-03-21
Fedora MEDIUM 5.5
CVE-2018-19872

An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.

Patch available
Fix from $1,600 2019-03-21
Fedora HIGH 7.5
CVE-2018-18898

The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic comp…

Fix: after 4.4.0
Fix from $1,950 2019-03-21
Fedora MEDIUM 5.5
CVE-2018-18849

In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.

Patch available
Fix from $1,600 2019-03-21
Fedora HIGH 7.5
CVE-2019-3833EPSS 15%

Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. …

Fix: after 2.6.9
Fix from $1,950 2019-03-14
Fedora MEDIUM 5.5
CVE-2019-9704

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the c…

Fix: 3.0pl1-133+
Fix from $1,600 2019-03-12
Fedora CRITICAL 9.8
CVE-2019-9687

PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.

Patch available
Fix from $2,300 2019-03-11
Fedora CRITICAL 9.8
CVE-2019-9631

Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

Patch available
Fix from $2,300 2019-03-08
Fedora MEDIUM 6.5
CVE-2018-14498

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer ov…

Fix: after 3.3.1
Fix from $1,600 2019-03-07
Fedora MEDIUM 6.5
CVE-2019-9211

There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that…

No fix yet
Fix from $1,600 2019-02-27
Fedora HIGH 8.8
CVE-2019-9199

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by…

Patch available
Fix from $1,950 2019-02-26
Fedora MEDIUM 5.5
CVE-2019-3812

QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() fun…

Fix: after 3.1.0
Fix from $1,600 2019-02-19
Fedora HIGH 7.8
CVE-2019-8376

An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be trigger…

No fix yet
Fix from $1,950 2019-02-17
Fedora HIGH 7.8
CVE-2019-8377

An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be trig…

No fix yet
Fix from $1,950 2019-02-17
Fedora HIGH 7.8
CVE-2019-8381

An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pc…

No fix yet
Fix from $1,950 2019-02-17
Fedora HIGH 8.1
CVE-2019-7639

An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins su…

No fix yet
Fix from $1,950 2019-02-08
Fedora CRITICAL 9.8
CVE-2019-6446EPSS 18%

An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code vi…

Fix: after 1.16.0
Fix from $2,300 2019-01-16