Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2019-0001

Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge s…

Mitigation only
Fix from $1,950 2019-01-15
Fedora HIGH 8.1
CVE-2019-6251

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause…

Fix: 2.24.1+
Fix from $1,950 2019-01-14
Fedora MEDIUM 5.5
CVE-2018-20592

In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnera…

No fix yet
Fix from $1,600 2018-12-30
Fedora MEDIUM 5.5
CVE-2018-20593

In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.

No fix yet
Fix from $1,600 2018-12-30
Fedora MEDIUM 6.5
CVE-2018-1000879

libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vuln…

Fix: 3.4.0+
Fix from $1,600 2018-12-20
Sssd MEDIUM 5.5
CVE-2018-16883

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. I…

Fix: 2.0.0+
Fix from $1,600 2018-12-19
Fedora HIGH 7.8
CVE-2018-16867

A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp…

Fix: after 3.0.0
Fix from $1,950 2018-12-12
Fedora MEDIUM 5.5
CVE-2018-20005

An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.

No fix yet
Fix from $1,600 2018-12-10
Fedora HIGH 7.5
CVE-2018-19591EPSS 6%

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socke…

Fix: after 2.28
Fix from $1,950 2018-12-04
Fedora CRITICAL 9.8
CVE-2018-18408

A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c…

Patch available
Fix from $2,300 2018-10-17
Fedora MEDIUM 5.5
CVE-2018-18407

A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The is…

Patch available
Fix from $1,600 2018-10-17
Fedora MEDIUM 5.5
CVE-2018-18409

A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leadi…

Patch available
Fix from $1,600 2018-10-17
Fedora CRITICAL 9.8
CVE-2018-17825

An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's t…

No fix yet
Fix from $2,300 2018-10-01
Fedora CRITICAL 9.8
CVE-2017-18342EPSS 6%

In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in versio…

Fix: 5.1+
Fix from $2,300 2018-06-27
Fedora HIGH 7.5
CVE-2018-1090

In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access …

Fix: 2.16.2+
Fix from $1,950 2018-06-18
Fedora MEDIUM 5.5
CVE-2018-10196

NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote att…

Patch available
Fix from $1,600 2018-05-30
Fedora HIGH 7.5
CVE-2018-1111EPSS 98%

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integratio…

No fix yet
Fix from $1,950 2018-05-17
389 Directory Server MEDIUM 5.9
CVE-2011-0704

389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modif…

Mitigation only
Fix from $1,600 2018-05-04
Fedora HIGH 7.1
CVE-2013-0159

The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial …

Patch available
Fix from $1,950 2018-05-01
Fedora HIGH 8.8
CVE-2018-3846

In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow over…

No fix yet
Fix from $1,950 2018-04-16
Fedora HIGH 8.8
CVE-2018-3848

In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbi…

Fix: 3.490+
Fix from $1,950 2018-04-16
Fedora HIGH 8.8
CVE-2018-3849

In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbi…

Fix: 3.490+
Fix from $1,950 2018-04-16
Fedora HIGH 7.8
CVE-2014-7271

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.

Fix: 0.10.0+
Fix from $1,950 2018-03-08
Fedora HIGH 7.8
CVE-2014-7272

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations…

Fix: 0.10.0+
Fix from $1,950 2018-03-08
Fedora HIGH 7.8
CVE-2014-3219

fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.…

Fix: 2.1.1+
Fix from $1,950 2018-02-09
Fedora CRITICAL 9.8
CVE-2014-3005EPSS 5%

XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allow…

Patch available
Fix from $2,300 2018-02-01
Fedora HIGH 8.8
CVE-2017-15365

sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.1…

Fix: 5.6.37-26.21-3 / 5.7.19-29.22-3+
Fix from $1,950 2018-01-25
389 Directory Server HIGH 8.1
CVE-2017-15135

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during th…

Fix: after 1.4.0.3
Fix from $1,950 2018-01-24
Fedora HIGH 7.8
CVE-2018-5345

A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbit…

Mitigation only
Fix from $1,950 2018-01-12
Fedora MEDIUM 5.5
CVE-2014-1859

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local …

Fix: after 1.8.0
Fix from $1,600 2018-01-08