Search

Found 3,839 results in 2453ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-9791 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con…
CVE-2019-9790 critical 9.5 FIX arch arch slesdebian debian 7y ago A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially e…
CVE-2019-9788 critical 9.5 FIX arch arch slesdebian debian 7y ago Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we pres…
CVE-2018-18506 critical 9.5 FIX arch arch slesdebian debian 7y ago When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to …
CVE-2019-11068 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu xmlsoftoraclenetapp 7y ago RHSA-2020:4464: libxslt security update (Moderate)
CVE-2019-11358 low 3.5 EXPFIX arch arch rockydebian debian 7y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2018-10895 critical 9.5 FIX arch archdebian debian 8y ago qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/s…
CVE-2017-15412 critical 9.5 FIX arch arch slesdebian debian 9y ago Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2014-4914 critical 9.8 9.8 debian debian zend 9y ago The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVE-2017-17864 low 3.3 3.3 FIX arch archdebian debian linux-kernel 9y ago kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentia…
CVE-2015-7224 critical 9.8 9.8 FIX debian debian puppet 9y ago puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host…
CVE-2017-17821 critical 9.8 9.8 FIX debian debian apple 9y ago WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other im…
CVE-2017-17807 low 3.3 3.3 FIX arch arch slesdebian debian 9y ago The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing …
CVE-2017-15897 low 3.1 3.1 FIX debian debian nodejs 9y ago Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This…
CVE-2017-15896 critical 9.1 9.1 FIX slesdebian debian nodejs 9y ago Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application dat…
CVE-2017-17499 critical 9.8 9.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
CVE-2017-17484 critical 9.8 9.8 FIX slesdebian debian icu-project 9y ago The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote a…
CVE-2017-17480 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu uclouvain 9y ago In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of serv…
CVE-2017-17479 critical 9.8 9.8 FIX slesdebian debian uclouvain 9y ago In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of servi…
CVE-2016-5713 critical 9.8 9.8 FIX debian debian puppet 9y ago Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to…
CVE-2017-17434 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also …
CVE-2017-17433 low 3.7 3.7 FIX arch arch slesdebian debian samba 9y ago The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_f…
CVE-2016-1253 critical 9.8 9.8 FIX debian debian debian 9y ago The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell …
CVE-2017-8822 low 3.7 3.7 FIX arch archdebian debian tor_project 9y ago In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick th…
CVE-2017-8818 critical 9.8 9.8 FIX arch archdebian debian haxx 9y ago curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too litt…
CVE-2017-8817 critical 9.8 9.8 FIX arch arch slesdebian debian haxx 9y ago The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact v…
CVE-2017-8816 critical 9.8 9.8 FIX arch arch slesdebian debian haxx 9y ago The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application cr…
CVE-2017-14746 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
CVE-2017-16943 critical 9.8 9.8 FIX arch archdebian debian exim 9y ago The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BD…
CVE-2017-16931 critical 9.8 9.8 FIX slesdebian debian xmlsoft 9y ago parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.
CVE-2017-15088 critical 9.8 9.8 FIX arch arch slesdebian debian mit 9y ago plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause …
CVE-2017-16926 critical 9.8 9.8 FIX debian debian ohcount_project 9y ago Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for Ohcount processing) t…
CVE-2017-16613 critical 9.8 9.8 debian debian openstack 9y ago An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieve…
CVE-2017-16840 critical 9.8 9.8 FIX arch archdebian debian ffmpeg 9y ago The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related t…
CVE-2017-16896 critical 9.8 9.8 FIX debian debian tt-rss 9y ago A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
CVE-2017-16845 critical 10.0 10.0 FIX slesdebian debianubuntu ubuntu qemu 9y ago hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
CVE-2017-1000215 critical 9.8 9.8 FIX slesdebian debian xrootd 9y ago ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
CVE-2017-1000206 critical 9.8 9.8 FIX debian debian htslib 9y ago samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution
CVE-2017-16872 critical 9.8 9.8 debian debian teluu 9y ago An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overf…
CVE-2017-1000158 critical 9.8 9.8 FIX slesdebian debian python 9y ago CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code ex…
CVE-2017-1000232 critical 9.8 9.8 FIX slesdebian debian nlnetlabs 9y ago A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.
CVE-2017-1000231 critical 9.8 9.8 FIX slesdebian debian nlnetlabs 9y ago A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
CVE-2017-1000228 critical 9.8 9.8 FIX debian debian ejs 9y ago nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
CVE-2017-16844 critical 9.8 9.8 FIX slesdebian debian procmail 9y ago Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code…
CVE-2017-8807 critical 9.1 9.1 FIX debian debian varnish-cachevarnish_cache_project 9y ago vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a V…
CVE-2017-1000248 critical 9.8 9.8 FIX debian debian redis-store 9y ago Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
CVE-2017-8809 critical 9.8 9.8 FIX arch archdebian debian mediawiki 9y ago api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
CVE-2017-16820 critical 9.8 9.8 FIX debian debian collectd 9y ago The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other imp…
CVE-2015-7501 critical 9.8 9.8 FIX debian debian redhat 9y ago Deserialization of Untrusted Data in Apache commons collections
CVE-2017-2922 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while l…
CVE-2017-2921 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to …
CVE-2017-2894 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow…
CVE-2017-2892 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory…
CVE-2017-2891 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed poi…
CVE-2017-16548 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (…
CVE-2017-16510 critical 9.8 9.8 FIX debian debian wordpress 9y ago WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "d…
CVE-2017-1000121 critical 9.8 9.8 FIX debian debian webkitgtk 9y ago The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subse…
CVE-2017-1000257 critical 9.1 9.1 FIX slesarch archdebian debian haxx 9y ago An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer …
CVE-2013-4366 critical 9.8 9.8 FIX debian debian apache 9y ago Hostname verification in Apache HttpClient 4.3 was disabled by default
CVE-2017-15597 critical 9.1 9.1 FIX slesdebian debian 9y ago An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not mat…
CVE-2015-3249 critical 9.8 9.8 FIX debian debian apache 9y ago The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary …
CVE-2014-3624 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
CVE-2017-16228 critical 9.8 9.8 FIX slesdebian debian dulwich_project 9y ago Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017…
CVE-2017-15994 critical 9.8 9.8 FIX arch archdebian debian samba 9y ago rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has signi…
CVE-2014-3600 critical 9.8 9.8 FIX debian debian apache 9y ago Improper Restriction of XML External Entity Reference in Apache ActiveMQ
CVE-2017-5081 low 3.3 3.3 FIX arch arch rhelmacos macos google 9y ago multiple issues in chromium
CVE-2017-15096 low 3.3 3.3 FIX debian debian gluster 9y ago A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
CVE-2012-3866 low 2.1 FIX debian debian puppetpuppetlabs 9y ago lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration in…
CVE-2012-3865 low 3.5 FIX debian debian puppetpuppetlabs 9y ago Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remot…
CVE-2012-3408 low 2.6 FIX debian debian puppetpuppetlabs 9y ago lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote att…
CVE-2012-1989 low 3.6 FIX debian debian puppetpuppetlabs 9y ago telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connect…
CVE-2012-4570 critical 9.8 9.8 FIX debian debian letodms_project 9y ago SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-15804 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
CVE-2011-1935 critical 9.8 9.8 FIX debian debian tcpdump 9y ago pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remote attackers to send arbitrary data while avoiding…
CVE-2017-15670 critical 9.8 9.8 FIX arch arch slesdebian debian gnu 9y ago The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories u…
CVE-2017-10346 critical 9.6 9.6 FIX sles rheldebian debian oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u14…
CVE-2017-10345 low 3.1 3.1 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE…
CVE-2017-10285 critical 9.6 9.6 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. E…
CVE-2017-8805 critical 9.1 9.1 FIX debian debian debian 9y ago Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
CVE-2015-7687 critical 9.8 9.8 FIX debian debianfedora fedora openbsd 9y ago Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mt…
CVE-2017-14952 critical 9.8 9.8 FIX arch arch slesdebian debian icu-project 9y ago Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector …
CVE-2017-12629 critical 9.8 10.0 EXPFIX debian debianubuntu ubuntu rhel apacheredhat 9y ago Remote code execution occurs in Apache Solr
CVE-2008-7315 critical 9.8 9.8 FIX debian debian cpan 9y ago UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
CVE-2014-9474 critical 9.8 9.8 FIX debian debian mpfr 9y ago Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors related to incorrect documentation for mpn_set_str.
CVE-2017-0903 critical 9.8 9.8 FIX slesubuntu ubuntudebian debian rubygems 9y ago RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted…
CVE-2017-15047 critical 9.8 9.8 FIX debian debian redislabsredis 9y ago The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by…
CVE-2017-15041 critical 9.8 9.8 FIX arch archdebian debian rhel golangredhat 9y ago Remote command execution via "go get" in cmd/go
CVE-2017-15032 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
CVE-2017-14491 critical 9.8 10.0 EXPFIX arch arch slesdebian debian thekelleyssusenvidia 9y ago multiple issues in dnsmasq
CVE-2017-12166 critical 9.8 9.8 FIX slesarch archdebian debian openvpn 9y ago OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
CVE-2017-0822 critical 9.8 9.8 debian debian 9y ago An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63787722.
CVE-2017-14493 critical 9.8 10.0 EXPFIX arch arch slesdebian debian thekelleys 9y ago multiple issues in dnsmasq
CVE-2017-14492 critical 9.8 10.0 EXPFIX arch arch slesdebian debian thekelleys 9y ago multiple issues in dnsmasq
CVE-2017-12814 critical 9.8 9.8 FIX debian debian perl 9y ago Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long en…
CVE-2015-7510 critical 9.8 9.8 FIX debian debian systemd_project 9y ago Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
CVE-2012-6696 critical 9.8 9.8 FIX debian debian inspircd 9y ago inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012-1836.
CVE-2017-14723 critical 9.8 9.8 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injec…
CVE-2017-7544 critical 9.1 9.1 FIX arch arch slesdebian debian libexif_project 9y ago libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data …
CVE-2017-12170 critical 9.8 9.8 FIX fedora fedoradebian debian pureftpd 9y ago Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with defau…
CVE-2015-5284 critical 9.8 9.8 FIX debian debian freeipa 9y ago ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.