Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libredwg HIGH 8.8
CVE-2020-21814

A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.

Patch available
Fix from $1,950 2021-05-17
Libredwg HIGH 8.8
CVE-2020-21816

A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.

Patch available
Fix from $1,950 2021-05-17
Libredwg HIGH 8.8
CVE-2020-21818

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.

Mitigation only
Fix from $1,950 2021-05-17
Libredwg HIGH 8.8
CVE-2020-21819

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.

Patch available
Fix from $1,950 2021-05-17
Libredwg MEDIUM 6.5
CVE-2020-21815

A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (appli…

Patch available
Fix from $1,600 2021-05-17
Libredwg MEDIUM 6.5
CVE-2020-21817

A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (applic…

Patch available
Fix from $1,600 2021-05-17
Libredwg HIGH 7.8
CVE-2020-21813

A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.

Patch available
Fix from $1,950 2021-05-17
Binutils HIGH 7.8
CVE-2021-20294

A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a …

Fix: 2.35.2+
Fix from $1,950 2021-04-29
Wget MEDIUM 6.1
CVE-2021-31879

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.

Fix: after 1.21.1
Fix from $1,600 2021-04-29
Guix MEDIUM 5.5
CVE-2021-27851

A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-dae…

Fix: 1.2.0+
Fix from $1,600 2021-04-26
Binutils MEDIUM 5.5
CVE-2021-20284

A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the nu…

No fix yet
Fix from $1,600 2021-03-26
Punbb MEDIUM 5.4
CVE-2021-28968

An issue was discovered in PunBB before 1.4.6. An XSS vulnerability in the [email] BBcode tag allows (with authentication) injecting arbitrary JavaSc…

Fix: 1.4.6+
Fix from $1,600 2021-03-22
Grub2 MEDIUM 6.4
CVE-2021-3418

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The b…

Fix: 2.06+
Fix from $1,600 2021-03-15
Binutils MEDIUM 5.5
CVE-2020-16590

A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated…

Patch available
Fix from $1,600 2020-12-09
Binutils MEDIUM 5.5
CVE-2020-16591

A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as …

Patch available
Fix from $1,600 2020-12-09
Binutils MEDIUM 5.5
CVE-2020-16593

A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in sca…

No fix yet
Fix from $1,600 2020-12-09
Binutils MEDIUM 5.5
CVE-2020-16599

A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bf…

Patch available
Fix from $1,600 2020-12-09
Glibc CRITICAL 9.8
CVE-1999-0199

manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's…

Fix: 2.2+
Fix from $2,300 2020-10-06
Bison MEDIUM 5.5
CVE-2020-24240

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is …

Patch available
Fix from $1,600 2020-08-25
Grub2 MEDIUM 6.7
CVE-2020-14309

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 byte…

Fix: 2.06+
Fix from $1,600 2020-07-30
Grub2 MEDIUM 6.4
CVE-2020-14308

In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads …

Fix: 2.06+
Fix from $1,600 2020-07-29
Libredwg MEDIUM 6.5
CVE-2020-15807

GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.

Fix: 0.11+
Fix from $1,600 2020-07-17
Libredwg CRITICAL 9.8
CVE-2019-20914

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in co…

Fix: after 0.9.3
Fix from $2,300 2020-07-16
Libredwg HIGH 8.8
CVE-2019-20912

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF.

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Libredwg HIGH 8.1
CVE-2019-20910

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a di…

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Libredwg HIGH 8.1
CVE-2019-20913

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity…

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Libredwg HIGH 8.1
CVE-2019-20915

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Libredwg MEDIUM 6.5
CVE-2019-20911

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.

Fix: after 0.9.3
Fix from $1,600 2020-07-16
Libredwg HIGH 7.5
CVE-2019-20909

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Bison MEDIUM 5.5
CVE-2020-14150

GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted …

Fix: 3.5.4+
Fix from $1,600 2020-06-15