VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2019-5809HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.02

    Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.

  • CVE-2019-5808HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.02

    Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5807HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.01

    Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5806HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-8324HigJun 17, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall…

  • CVE-2019-12450CriMay 29, 2019
    risk 0.57cvss 9.8epss 0.03

    file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

  • CVE-2019-11506HigApr 24, 2019
    risk 0.57cvss 8.8epss 0.03

    In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file.…

  • CVE-2019-11505HigApr 24, 2019
    risk 0.57cvss 8.8epss 0.03

    In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This…

  • CVE-2019-2698HigApr 23, 2019
    risk 0.57cvss 8.1epss 0.12

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.…

  • CVE-2019-11071HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.03

    SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.

  • CVE-2019-11068CriApr 10, 2019
    risk 0.57cvss 9.8epss 0.05

    libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

  • CVE-2019-6116HigMar 21, 2019
    risk 0.57cvss 7.8epss 0.43

    In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

  • CVE-2018-17937HigMar 13, 2019
    risk 0.57cvss 8.8epss 0.03

    gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs.

  • CVE-2019-9656HigMar 11, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.

  • CVE-2018-12389HigFeb 28, 2019
    risk 0.57cvss 8.8epss 0.02

    Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability…

  • CVE-2019-9200HigFeb 26, 2019
    risk 0.57cvss 8.8epss 0.03

    A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly…

  • CVE-2019-7164CriFeb 20, 2019
    risk 0.57cvss 9.8epss 0.04

    SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

  • CVE-2019-5783HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.01

    Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.

  • CVE-2019-5774HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.

  • CVE-2019-5772HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-5770HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.03

    Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2019-5769HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5764HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.01

    Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5763HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5762HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.03

    Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.

  • CVE-2019-5760HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.01

    Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5758HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5757HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.02

    An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

  • CVE-2019-5756HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.03

    Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.

  • CVE-2019-8907HigFeb 18, 2019
    risk 0.57cvss 8.8epss 0.03

    do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.

  • CVE-2019-7638HigFeb 8, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.

  • CVE-2019-7637HigFeb 8, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.

  • CVE-2019-7577HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.

  • CVE-2019-7576HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).

  • CVE-2019-7575HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.

  • CVE-2019-7574HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.

  • CVE-2019-7573HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).

  • CVE-2019-7572HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.

  • CVE-2019-6978CriJan 28, 2019
    risk 0.57cvss 9.8epss 0.04

    The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.

  • CVE-2019-6245HigJan 13, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call itself recursively. There can be…

  • CVE-2018-6174HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.03

    Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2018-6170HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    A bad cast in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2018-6162HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-6153HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.

  • CVE-2018-6151HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension.

  • CVE-2018-6144HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file.

  • CVE-2018-6141HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2018-6140HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.03

    Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

  • CVE-2018-6139HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

  • CVE-2018-6124HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

Page 31 of 210