Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2019-3858EPSS 6% An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker… Fedora 1.8.1+ Fix from $2,3002019-03-21 HIGH 8.8 CVE-2019-3855EPSS 9% An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the serve… Fedora Patch available Fix from $1,9502019-03-21 HIGH 8.8 CVE-2019-3871EPSS 13% A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user whe… Fedora 4.0.7 / 4.1.7+ Fix from $1,9502019-03-21 MEDIUM 6.5 CVE-2019-9903 PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.… Fedora No fix yet Fix from $1,6002019-03-21 CRITICAL 9.8 CVE-2019-9895 In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding. Fedora 0.71+ Fix from $2,3002019-03-21 CRITICAL 9.8 CVE-2019-9898 Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71. Fedora 0.71+ Fix from $2,3002019-03-21 HIGH 7.5 CVE-2019-9894 A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification. Fedora 0.71+ Fix from $1,9502019-03-21 HIGH 7.5 CVE-2019-9897 Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71. Fedora 0.71+ Fix from $1,9502019-03-21 HIGH 7.8 CVE-2019-6778 In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow. Fedora Patch available Fix from $1,9502019-03-21 MEDIUM 5.5 CVE-2019-6501 In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations. Fedora Patch available Fix from $1,6002019-03-21 HIGH 7.8 CVE-2019-6116EPSS 43% In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. Fedora Patch available Fix from $1,9502019-03-21 HIGH 7.5 CVE-2019-5885 Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and… Fedora 0.34.0.1+ Fix from $1,9502019-03-21 CRITICAL 9.1 CVE-2019-3859EPSS 6% An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote att… Fedora 1.8.1+ Fix from $2,3002019-03-21 CRITICAL 9.1 CVE-2019-3862EPSS 8% An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no paylo… Fedora 1.8.1+ Fix from $2,3002019-03-21 MEDIUM 5.5 CVE-2018-19872 An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp. Fedora Patch available Fix from $1,6002019-03-21 HIGH 7.5 CVE-2018-18898 The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic comp… Fedora after 4.4.0 Fix from $1,9502019-03-21 MEDIUM 5.5 CVE-2018-18849 In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value. Fedora Patch available Fix from $1,6002019-03-21 HIGH 7.5 CVE-2019-3833EPSS 15% Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. … Fedora after 2.6.9 Fix from $1,9502019-03-14 MEDIUM 5.5 CVE-2019-9704 Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the c… Fedora 3.0pl1-133+ Fix from $1,6002019-03-12 CRITICAL 9.8 CVE-2019-9687 PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. Fedora Patch available Fix from $2,3002019-03-11 CRITICAL 9.8 CVE-2019-9631 Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. Fedora Patch available Fix from $2,3002019-03-08 MEDIUM 6.5 CVE-2018-14498 get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer ov… Fedora after 3.3.1 Fix from $1,6002019-03-07 MEDIUM 6.5 CVE-2019-9211 There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that… Fedora No fix yet Fix from $1,6002019-02-27 HIGH 8.8 CVE-2019-9199 PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by… Fedora Patch available Fix from $1,9502019-02-26 MEDIUM 5.5 CVE-2019-3812 QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() fun… Fedora after 3.1.0 Fix from $1,6002019-02-19 HIGH 7.8 CVE-2019-8376 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be trigger… Fedora No fix yet Fix from $1,9502019-02-17 HIGH 7.8 CVE-2019-8377 An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be trig… Fedora No fix yet Fix from $1,9502019-02-17 HIGH 7.8 CVE-2019-8381 An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pc… Fedora No fix yet Fix from $1,9502019-02-17 HIGH 8.1 CVE-2019-7639 An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins su… Fedora No fix yet Fix from $1,9502019-02-08 CRITICAL 9.8 CVE-2019-6446EPSS 18% An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code vi… Fedora after 1.16.0 Fix from $2,3002019-01-16