Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-0316 | 2 Microsoft, Nvidia | 2 Windows, Geforce Experience | 2019-11-07 | 4.6 MEDIUM | 7.8 HIGH |
In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges. | |||||
CVE-2010-2490 | 2 Debian, Mumble | 2 Debian Linux, Mumble | 2019-11-06 | 4.0 MEDIUM | 6.5 MEDIUM |
Mumble: murmur-server has DoS due to malformed client query | |||||
CVE-2013-4103 | 1 Cryptocat Project | 1 Cryptocat | 2019-11-06 | 7.5 HIGH | 9.8 CRITICAL |
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | |||||
CVE-2018-1000002 | 1 Nic | 1 Knot Resolver | 2019-11-06 | 4.3 MEDIUM | 3.7 LOW |
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay. | |||||
CVE-2013-4751 | 3 Fedoraproject, Redhat, Sensiolabs | 3 Fedora, Enterprise Linux, Symfony | 2019-11-06 | 4.9 MEDIUM | 8.1 HIGH |
php-symfony2-Validator has loss of information during serialization | |||||
CVE-2013-0178 | 1 Redislabs | 1 Redis | 2019-11-06 | 3.6 LOW | 5.5 MEDIUM |
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm. | |||||
CVE-2013-0180 | 1 Redislabs | 1 Redis | 2019-11-06 | 3.6 LOW | 5.5 MEDIUM |
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds. | |||||
CVE-2015-8980 | 4 Fedoraproject, Opensuse, Php-gettext Project and 1 more | 4 Fedora, Leap, Php-gettext and 1 more | 2019-11-06 | 7.5 HIGH | 9.8 CRITICAL |
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. | |||||
CVE-2010-2061 | 1 Rpcbind Project | 1 Rpcbind | 2019-11-05 | 7.2 HIGH | 7.8 HIGH |
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started. | |||||
CVE-2013-3718 | 4 Debian, Gnome, Opensuse and 1 more | 4 Debian Linux, Evince, Opensuse and 1 more | 2019-11-05 | 4.3 MEDIUM | 5.5 MEDIUM |
evince is missing a check on number of pages which can lead to a segmentation fault | |||||
CVE-2010-3667 | 1 Typo3 | 1 Typo3 | 2019-11-05 | 5.0 MEDIUM | 5.3 MEDIUM |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element. | |||||
CVE-2012-6125 | 1 Call-cc | 1 Chicken | 2019-11-05 | 7.5 HIGH | 9.8 CRITICAL |
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions. | |||||
CVE-2013-2259 | 1 Cryptocat Project | 1 Cryptocat | 2019-11-05 | 7.5 HIGH | 9.8 CRITICAL |
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | |||||
CVE-2013-4100 | 1 Cryptocat Project | 1 Cryptocat | 2019-11-05 | 5.0 MEDIUM | 7.5 HIGH |
Cryptocat before 2.0.22 has Remote Denial of Service via username | |||||
CVE-2013-2227 | 2 Debian, Glpi-project | 2 Debian Linux, Glpi | 2019-11-04 | 5.0 MEDIUM | 7.5 HIGH |
GLPI 0.83.7 has Local File Inclusion in common.tabs.php. | |||||
CVE-2012-0694 | 1 Sugarcrm | 1 Sugarcrm | 2019-11-01 | 7.5 HIGH | 9.8 CRITICAL |
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. | |||||
CVE-2010-3375 | 1 Qtparted Project | 1 Qtparted | 2019-11-01 | 7.5 HIGH | 9.8 CRITICAL |
qtparted has insecure library loading which may allow arbitrary code execution | |||||
CVE-2010-3373 | 2 Debian, Grsecurity | 2 Debian Linux, Paxtest | 2019-11-01 | 2.1 LOW | 5.5 MEDIUM |
paxtest handles temporary files insecurely | |||||
CVE-2002-2444 | 1 Snoopy Project | 1 Snoopy | 2019-11-01 | 7.5 HIGH | 9.8 CRITICAL |
Snoopy before 2.0.0 has a security hole in exec cURL | |||||
CVE-2018-7208 | 2 Gnu, Redhat | 4 Binutils, Enterprise Linux Desktop, Enterprise Linux Server and 1 more | 2019-10-30 | 6.8 MEDIUM | 7.8 HIGH |
In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted file, as demonstrated by objcopy of a COFF object. |