VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2018-19134HigDec 20, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type…

  • CVE-2018-20196HigDec 18, 2018
    risk 0.51cvss 7.8epss 0.01

    There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is…

  • CVE-2018-19962HigDec 8, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

  • CVE-2018-19961HigDec 8, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.

  • CVE-2018-19543HigNov 26, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

  • CVE-2018-19492HigNov 23, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This…

  • CVE-2018-19491HigNov 23, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue…

  • CVE-2018-19490HigNov 23, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right…

  • CVE-2018-19477HigNov 23, 2018
    risk 0.51cvss 7.8epss 0.03

    psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.

  • CVE-2018-19476HigNov 23, 2018
    risk 0.51cvss 7.8epss 0.03

    psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.

  • CVE-2018-19475HigNov 23, 2018
    risk 0.51cvss 7.8epss 0.10

    psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

  • CVE-2018-19216HigNov 12, 2018
    risk 0.51cvss 7.8epss 0.01

    Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

  • CVE-2018-9516HigNov 6, 2018
    risk 0.51cvss 7.8epss 0.00

    In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android…

  • CVE-2018-9422HigNov 6, 2018
    risk 0.51cvss 7.8epss 0.00

    In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID:…

  • CVE-2018-18718HigOct 29, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.

  • CVE-2018-18654HigOct 26, 2018
    risk 0.51cvss 7.8epss 0.00

    Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process copies xr there, and then replace the entire contents of…

  • CVE-2016-10729HigOct 24, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command…

  • CVE-2018-12379HigOct 18, 2018
    risk 0.51cvss 7.8epss 0.00

    When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in…

  • CVE-2015-9268HigOct 1, 2018
    risk 0.51cvss 7.8epss 0.02

    Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.

  • CVE-2018-17183HigSep 19, 2018
    risk 0.51cvss 7.8epss 0.02

    Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.

  • CVE-2018-11781HigSep 17, 2018
    risk 0.51cvss 7.8epss 0.01

    Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

  • CVE-2018-16741HigSep 13, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is possible to use the ||, &&, or > characters within a file created by the "faxq-helper activate…

  • CVE-2018-16802HigSep 10, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to…

  • CVE-2018-16585HigSep 6, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to…

  • CVE-2018-16543HigSep 5, 2018
    risk 0.51cvss 7.8epss 0.01

    In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

  • CVE-2018-16540HigSep 5, 2018
    risk 0.51cvss 7.8epss 0.02

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.

  • CVE-2018-16513HigSep 5, 2018
    risk 0.51cvss 7.8epss 0.01

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.

  • CVE-2018-16511HigSep 5, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.

  • CVE-2018-6555HigSep 4, 2018
    risk 0.51cvss 7.8epss 0.01

    The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an…

  • CVE-2018-15911HigAug 28, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.

  • CVE-2018-15910HigAug 27, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.

  • CVE-2018-15909HigAug 27, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.

  • CVE-2018-15908HigAug 27, 2018
    risk 0.51cvss 7.8epss 0.02

    In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.

  • CVE-2018-10902HigAug 21, 2018
    risk 0.51cvss 7.8epss 0.01

    It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local…

  • CVE-2018-1000222HigAug 20, 2018
    risk 0.51cvss 8.8epss 0.04

    Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been…

  • CVE-2018-1000637HigAug 20, 2018
    risk 0.51cvss 7.8epss 0.02

    zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability…

  • CVE-2018-14682HigJul 28, 2018
    risk 0.51cvss 8.8epss 0.04

    An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.

  • CVE-2018-14681HigJul 28, 2018
    risk 0.51cvss 8.8epss 0.04

    An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.

  • CVE-2018-14678HigJul 28, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and…

  • CVE-2018-1056HigJul 27, 2018
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.

  • CVE-2018-5848HigJun 12, 2018
    risk 0.51cvss 7.8epss 0.00

    In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using…

  • CVE-2018-5158HigJun 11, 2018
    risk 0.51cvss 8.8epss 0.10

    The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR <…

  • CVE-2017-7814HigJun 11, 2018
    risk 0.51cvss 7.8epss 0.01

    File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables…

  • CVE-2018-10380HigMay 8, 2018
    risk 0.51cvss 7.8epss 0.00

    kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

  • CVE-2018-3836HigApr 24, 2018
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an…

  • CVE-2017-2918HigApr 24, 2018
    risk 0.51cvss 7.8epss 0.03

    An exploitable integer overflow exists in the Image loading functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the…

  • CVE-2017-2908HigApr 24, 2018
    risk 0.51cvss 7.8epss 0.02

    An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of…

  • CVE-2017-2907HigApr 24, 2018
    risk 0.51cvss 7.8epss 0.02

    An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the…

  • CVE-2017-2906HigApr 24, 2018
    risk 0.51cvss 7.8epss 0.02

    An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the…

  • CVE-2017-2905HigApr 24, 2018
    risk 0.51cvss 7.8epss 0.02

    An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context…

Page 55 of 210