VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2019-1010305MedJul 15, 2019
    risk 0.00cvss 5.5epss 0.02

    libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is:…

  • CVE-2019-1010319MedJul 11, 2019
    risk 0.00cvss 5.5epss 0.01

    WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is:…

  • CVE-2019-1010317MedJul 11, 2019
    risk 0.00cvss 5.5epss 0.01

    WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is:…

  • CVE-2019-1010315MedJul 11, 2019
    risk 0.00cvss 5.5epss 0.02

    WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tries to parse a .wav file. The component is: ParseDsdiffHeaderConfig (dsdiff.c:282). The attack vector is: Maliciously crafted .wav…

  • CVE-2019-13504MedJul 11, 2019
    risk 0.00cvss 6.5epss 0.02

    There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

  • CVE-2019-13224CriJul 10, 2019
    risk 0.00cvss 9.8epss 0.04

    A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a…

  • CVE-2019-13454MedJul 9, 2019
    risk 0.00cvss 6.5epss 0.04

    ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.

  • CVE-2019-13311MedJul 5, 2019
    risk 0.00cvss 6.5epss 0.03

    ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.

  • CVE-2019-13309MedJul 5, 2019
    risk 0.00cvss 6.5epss 0.03

    ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.

  • CVE-2019-13308HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.

  • CVE-2019-13307HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.

  • CVE-2019-13306HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.

  • CVE-2019-13305HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

  • CVE-2019-13304HigJul 5, 2019
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.

  • CVE-2019-13301MedJul 5, 2019
    risk 0.00cvss 6.5epss 0.03

    ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.

  • CVE-2019-13300HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.

  • CVE-2019-13297HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.

  • CVE-2019-13295HigJul 5, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

  • CVE-2019-13164HigJul 3, 2019
    risk 0.00cvss 7.8epss 0.01

    qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.

  • CVE-2019-13137MedJul 1, 2019
    risk 0.00cvss 6.5epss 0.02

    ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.

  • CVE-2019-13135HigJul 1, 2019
    risk 0.00cvss 8.8epss 0.03

    ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.

  • CVE-2019-13114MedJun 30, 2019
    risk 0.00cvss 6.5epss 0.02

    http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.

  • CVE-2019-13112MedJun 30, 2019
    risk 0.00cvss 6.5epss 0.02

    A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.

  • CVE-2019-13110MedJun 30, 2019
    risk 0.00cvss 6.5epss 0.02

    A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.

  • CVE-2019-12973MedJun 26, 2019
    risk 0.00cvss 5.5epss 0.03

    In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

  • CVE-2018-20847HigJun 26, 2019
    risk 0.00cvss 8.8epss 0.02

    An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

  • CVE-2019-12817HigJun 25, 2019
    risk 0.00cvss 7.0epss 0.00

    arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.

  • CVE-2019-10160CriJun 7, 2019
    risk 0.00cvss 9.8epss 0.05

    A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and…

  • CVE-2019-12111HigMay 15, 2019
    risk 0.00cvss 7.5epss 0.03

    A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.

  • CVE-2019-11833MedMay 15, 2019
    risk 0.00cvss 5.5epss 0.01

    fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.

  • CVE-2019-11884LowMay 10, 2019
    risk 0.00cvss 3.3epss 0.01

    The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.

  • CVE-2019-11815HigMay 8, 2019
    risk 0.00cvss 8.1epss 0.04

    An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.

  • CVE-2019-11810HigMay 7, 2019
    risk 0.00cvss 7.5epss 0.06

    An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.

  • CVE-2018-20836HigMay 7, 2019
    risk 0.00cvss 8.1epss 0.05

    An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.

  • CVE-2019-10131HigApr 30, 2019
    risk 0.00cvss 7.1epss 0.01

    An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.

  • CVE-2019-11498MedApr 24, 2019
    risk 0.00cvss 6.5epss 0.03

    WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate…

  • CVE-2019-11487HigApr 23, 2019
    risk 0.00cvss 7.8epss 0.01

    The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c,…

  • CVE-2019-11486HigApr 23, 2019
    risk 0.00cvss 7.0epss 0.00

    The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.

  • CVE-2019-11338HigApr 19, 2019
    risk 0.00cvss 8.8epss 0.02

    libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

  • CVE-2018-16878MedApr 18, 2019
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS

  • CVE-2018-16877HigApr 18, 2019
    risk 0.00cvss 7.8epss 0.00

    A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.

  • CVE-2019-11222HigApr 15, 2019
    risk 0.00cvss 7.8epss 0.01

    gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.

  • CVE-2019-3832MedMar 21, 2019
    risk 0.00cvss 5.5epss 0.01

    It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

  • CVE-2018-20178HigMar 15, 2019
    risk 0.00cvss 7.5epss 0.04

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).

  • CVE-2018-20175HigMar 15, 2019
    risk 0.00cvss 7.5epss 0.04

    rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).

  • CVE-2019-9718MedMar 12, 2019
    risk 0.00cvss 6.5epss 0.02

    In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

  • CVE-2019-9658MedMar 11, 2019
    risk 0.00cvss 5.3epss 0.04

    Checkstyle before 8.18 loads external DTDs by default.

  • CVE-2018-20763HigFeb 6, 2019
    risk 0.00cvss 7.8epss 0.01

    In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.

  • CVE-2018-20762HigFeb 6, 2019
    risk 0.00cvss 7.8epss 0.01

    GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.

  • CVE-2018-20761HigFeb 6, 2019
    risk 0.00cvss 7.8epss 0.01

    GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.

Page 184 of 210