Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Patch MEDIUM 5.5
CVE-2019-20633

GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of ser…

Fix: after 2.7.6
Fix from $1,600 2020-03-25
Screen CRITICAL 9.8
CVE-2020-9366

A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, cou…

Fix: 4.8.0+
Fix from $2,300 2020-02-24
Aspell CRITICAL 9.1
CVE-2019-20433

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 …

Fix: 0.60.8+
Fix from $2,300 2020-01-27
Coreutils CRITICAL 9.8
CVE-2015-4042

Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (ap…

Fix: after 8.23
Fix from $2,300 2020-01-24
Coreutils HIGH 7.8
CVE-2015-4041

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the nu…

Fix: after 8.23
Fix from $1,950 2020-01-24
Gnump3d HIGH 7.8
CVE-2019-3697

UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user g…

Fix: after 3.0
Fix from $1,950 2020-01-24
Libredwg HIGH 8.8
CVE-2020-6609

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

Patch available
Fix from $1,950 2020-01-08
Libredwg HIGH 8.1
CVE-2020-6612

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.

No fix yet
Fix from $1,950 2020-01-08
Libredwg HIGH 8.1
CVE-2020-6613

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.

No fix yet
Fix from $1,950 2020-01-08
Libredwg HIGH 8.1
CVE-2020-6614

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.

No fix yet
Fix from $1,950 2020-01-08
Libredwg MEDIUM 6.5
CVE-2020-6610

GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.

No fix yet
Fix from $1,600 2020-01-08
Libredwg MEDIUM 6.5
CVE-2020-6611

GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.

No fix yet
Fix from $1,600 2020-01-08
Libredwg MEDIUM 6.5
CVE-2020-6615

GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

No fix yet
Fix from $1,600 2020-01-08
Libredwg HIGH 8.8
CVE-2019-20010

An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.

No fix yet
Fix from $1,950 2019-12-27
Libredwg HIGH 8.8
CVE-2019-20011

An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.

No fix yet
Fix from $1,950 2019-12-27
Libredwg HIGH 8.8
CVE-2019-20014

An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.

Fix: 0.9.3+
Fix from $1,950 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20009

An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private…

Fix: 0.9.3+
Fix from $1,600 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20012

An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.…

No fix yet
Fix from $1,600 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20013

An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spe…

Fix: 0.9.3+
Fix from $1,600 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20015

An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in…

No fix yet
Fix from $1,600 2019-12-27
Grub2 MEDIUM 5.9
CVE-2019-14865

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting …

Mitigation only
Fix from $1,600 2019-11-29
Bash HIGH 7.8
CVE-2019-18276

An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal…

Fix: after 5.0
Fix from $1,950 2019-11-28
Serveez HIGH 7.5
CVE-2019-16200

GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a …

Fix: after 0.2.2
Fix from $1,950 2019-11-20
Gnusound CRITICAL 9.8
CVE-2012-0824

gnusound 0.7.5 has format string issue

Patch available
Fix from $2,300 2019-11-19
Mailutils HIGH 7.8
CVE-2019-18862

maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.

Fix: 3.8+
Fix from $1,950 2019-11-11
Gcc HIGH 7.8
CVE-2002-2439

Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.

Fix: 4.8.0+
Fix from $1,950 2019-10-23
Libidn2 HIGH 7.5
CVE-2019-12290

GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it p…

Fix: 2.2.0+
Fix from $1,950 2019-10-22
Libidn2 CRITICAL 9.8
CVE-2019-18224

idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.

Fix: 2.1.1+
Fix from $2,300 2019-10-21
Guix HIGH 7.8
CVE-2019-18192

GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world…

Patch available
Fix from $1,950 2019-10-17
Cflow MEDIUM 6.5
CVE-2019-16165

GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.

Fix: after 1.6
Fix from $1,600 2019-09-09