VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2018-14464HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

  • CVE-2018-14463HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

  • CVE-2018-14462HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

  • CVE-2018-14461HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

  • CVE-2019-16276HigSep 30, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

  • CVE-2019-9433MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.03

    In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9371MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.03

    In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9325MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.03

    In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-16713MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.

  • CVE-2019-16711MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.

  • CVE-2019-16710MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.

  • CVE-2019-16708MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.

  • CVE-2019-16391MedSep 17, 2019
    risk 0.42cvss 6.5epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.

  • CVE-2018-21016MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

  • CVE-2018-21015MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

  • CVE-2019-16275MedSep 12, 2019
    risk 0.42cvss 6.5epss 0.01

    hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The…

  • CVE-2019-16237HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.01

    Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.

  • CVE-2019-16236HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.02

    Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.

  • CVE-2019-16235HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.01

    Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.

  • CVE-2019-16163HigSep 9, 2019
    risk 0.42cvss 7.5epss 0.03

    Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.

  • CVE-2015-9383MedSep 3, 2019
    risk 0.42cvss 6.5epss 0.02

    FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.

  • CVE-2015-9382MedSep 3, 2019
    risk 0.42cvss 6.5epss 0.02

    FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.

  • CVE-2019-15531MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

  • CVE-2019-13458MedAug 21, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in…

  • CVE-2019-12746MedAug 21, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties.…

  • CVE-2019-15133MedAug 17, 2019
    risk 0.42cvss 6.5epss 0.02

    In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.

  • CVE-2019-14380MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.

  • CVE-2019-14443MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.

  • CVE-2019-14442MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted file.

  • CVE-2019-14370MedJul 28, 2019
    risk 0.42cvss 6.5epss 0.01

    In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.

  • CVE-2019-14369MedJul 28, 2019
    risk 0.42cvss 6.5epss 0.01

    Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file.

  • CVE-2019-9959MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.02

    The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by…

  • CVE-2019-13626MedJul 17, 2019
    risk 0.42cvss 6.5epss 0.02

    SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

  • CVE-2019-10193HigJul 11, 2019
    risk 0.42cvss 7.2epss 0.24

    A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of…

  • CVE-2019-12470MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2019-12469MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2019-13147MedJul 2, 2019
    risk 0.42cvss 6.5epss 0.02

    In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.

  • CVE-2019-5837MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5834MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-5832MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5830MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5818MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.

  • CVE-2019-5814MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5810MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-5805MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-9892MedMay 22, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will…

  • CVE-2019-12221MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.

  • CVE-2019-12216MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.

  • CVE-2019-12213MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.

  • CVE-2019-11474MedApr 23, 2019
    risk 0.42cvss 6.5epss 0.02

    coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.

Page 99 of 210