Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-20477EPSS 5% PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a … Fedora after 5.1.2 Fix from $2,3002020-02-19 CRITICAL 9.8 CVE-2020-8518EPSS 72% Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. Fedora No fix yet Fix from $2,3002020-02-17 HIGH 7.5 CVE-2019-20454 An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF… Fedora 8.2.12 / 9.0.6+ Fix from $1,9502020-02-14 CRITICAL 9.8 CVE-2020-8955 irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and ap… Fedora after 2.7 Fix from $2,3002020-02-12 HIGH 7.5 CVE-2020-7046EPSS 51% lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the u… Fedora 2.3.9.3+ Fix from $1,9502020-02-12 MEDIUM 5.3 CVE-2020-7957 The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet an… Fedora 2.3.9.3+ Fix from $1,6002020-02-12 HIGH 7.5 CVE-2018-14553 gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific functi… Fedora after 2.2.5 Fix from $1,9502020-02-11 HIGH 7.5 CVE-2013-4572 The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache sessio… Fedora 1.19.9 / 1.20.8+ Fix from $1,9502020-02-06 HIGH 7.5 CVE-2010-5304 A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use thi… Fedora 0.9.9+ Fix from $1,9502020-02-05 HIGH 7.5 CVE-2019-12528EPSS 10% An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as… Fedora 4.10+ Fix from $1,9502020-02-04 MEDIUM 6.5 CVE-2019-20446 In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processi… Fedora 2.40.21 / 2.42.8+ Fix from $1,6002020-02-02 HIGH 7.5 CVE-2011-4088 ABRT might allow attackers to obtain sensitive information from crash reports. Fedora Mitigation only Fix from $1,9502020-01-31 MEDIUM 5.9 CVE-2013-0294 packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attacke… Fedora 2.1+ Fix from $1,6002020-01-28 HIGH 7.5 CVE-2014-2581 Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit. Fedora 1.1.1+ Fix from $1,9502020-01-28 HIGH 7.5 CVE-2020-7238 Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line)… Fedora No fix yet Fix from $1,9502020-01-27 HIGH 7.5 CVE-2015-9541 Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue … Fedora 5.12.8+ Fix from $1,9502020-01-24 MEDIUM 6.5 CVE-2015-5745 Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service … Fedora 2.4.0+ Fix from $1,6002020-01-23 MEDIUM 6.5 CVE-2015-5239 Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT m… Fedora 2.1.0+ Fix from $1,6002020-01-23 MEDIUM 6.5 CVE-2015-5278 The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash… Fedora 2.4.0.1+ Fix from $1,6002020-01-23 HIGH 7.5 CVE-2020-7595EPSS 8% xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. Fedora 3.0+ Fix from $1,9502020-01-21 HIGH 7.5 CVE-2019-19886 Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the serve… Fedora after 3.0.3 Fix from $1,9502020-01-21 MEDIUM 6.5 CVE-2019-14907 All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or abov… Fedora 4.9.18 / 4.10.12+ Fix from $1,6002020-01-21 MEDIUM 6.1 CVE-2019-19547 Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue tha… Fedora 4.3.0+ Fix from $1,6002020-01-13 HIGH 8.8 CVE-2020-6860 libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute. Fedora No fix yet Fix from $1,9502020-01-13 HIGH 7.5 CVE-2020-6851 OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimen… Fedora Patch available Fix from $1,9502020-01-13 MEDIUM 5.9 CVE-2020-6750 GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when config… Fedora after 2.62.4 Fix from $1,6002020-01-09 MEDIUM 6.7 CVE-2019-5188 A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cau… Fedora after 1.45.4 Fix from $1,6002020-01-08 HIGH 8.8 CVE-2020-5395 FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. Fedora Patch available Fix from $1,9502020-01-03 MEDIUM 6.1 CVE-2012-4451 Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTM… Fedora 2.0.1+ Fix from $1,6002020-01-03 HIGH 7.8 CVE-2013-4161 gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security iss… Fedora Mitigation only Fix from $1,9502019-12-31