VYPR

Vendor CVEs

Canonical

All CVEs

4,263 total · sorted by risk
  • CVE-2020-12398HigJul 9, 2020
    risk 0.49cvss 7.5epss 0.01

    If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

  • CVE-2020-14303HigJul 6, 2020
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.

  • CVE-2020-8161HigJul 2, 2020
    risk 0.49cvss 8.6epss 0.03

    A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

  • CVE-2018-21247HigJun 17, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

  • CVE-2020-0198HigJun 11, 2020
    risk 0.49cvss 7.5epss 0.04

    In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-13757HigJun 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application…

  • CVE-2020-3811HigMay 26, 2020
    risk 0.49cvss 7.5epss 0.02

    qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

  • CVE-2020-12663HigMay 19, 2020
    risk 0.49cvss 7.5epss 0.04

    Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.

  • CVE-2020-12662HigMay 19, 2020
    risk 0.49cvss 7.5epss 0.03

    Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

  • CVE-2020-3341HigMay 13, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read.…

  • CVE-2020-3327HigMay 13, 2020
    risk 0.49cvss 7.5epss 0.05

    A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An…

  • CVE-2020-12783HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.05

    Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

  • CVE-2020-12243HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.04

    In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).

  • CVE-2020-12059HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

  • CVE-2019-12520HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the…

  • CVE-2020-2816HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.03

    Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of…

  • CVE-2020-11655HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.04

    SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

  • CVE-2019-14855HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

  • CVE-2020-7062HigFeb 27, 2020
    risk 0.49cvss 7.5epss 0.04

    In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to…

  • CVE-2020-9327HigFeb 21, 2020
    risk 0.49cvss 7.5epss 0.04

    In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.

  • CVE-2020-6062HigFeb 19, 2020
    risk 0.49cvss 7.5epss 0.06

    An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.

  • CVE-2020-3123HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds…

  • CVE-2020-8517HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process…

  • CVE-2020-8449HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • CVE-2019-9674HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.06

    Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

  • CVE-2020-7595HigJan 21, 2020
    risk 0.49cvss 7.5epss 0.08

    xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

  • CVE-2019-15961HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing…

  • CVE-2019-17011HigJan 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

  • CVE-2019-17010HigJan 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox…

  • CVE-2019-5188HigJan 8, 2020
    risk 0.49cvss 7.5epss 0.01

    A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this…

  • CVE-2013-4357HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.03

    The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

  • CVE-2019-18804HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.04

    DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.

  • CVE-2019-9232HigSep 27, 2019
    risk 0.49cvss 7.5epss 0.05

    In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-16869HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.08

    Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

  • CVE-2019-10092MedSep 26, 2019
    risk 0.49cvss 6.1epss 0.81

    In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server…

  • CVE-2019-5094HigSep 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

  • CVE-2019-16095HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.

  • CVE-2019-16094HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.

  • CVE-2019-16091HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.

  • CVE-2019-15099HigAug 16, 2019
    risk 0.49cvss 7.5epss 0.04

    drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

  • CVE-2019-14494HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

  • CVE-2019-13565HigJul 26, 2019
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity…

  • CVE-2019-13619HigJul 17, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.

  • CVE-2019-10192HigJul 11, 2019
    risk 0.49cvss 7.2epss 0.26

    A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL…

  • CVE-2019-12295HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.04

    In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.

  • CVE-2019-12211HigMay 20, 2019
    risk 0.49cvss 7.5epss 0.04

    When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered, resulting in a heap overflow.

  • CVE-2019-2632HigApr 23, 2019
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple…

  • CVE-2019-2602HigApr 23, 2019
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2019-9628HigApr 11, 2019
    risk 0.49cvss 7.5epss 0.02

    The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and…

  • CVE-2019-10903HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.

Page 20 of 86