Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.1
CVE-2022-23482

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux CRITICAL 9.1
CVE-2022-23483

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux CRITICAL 9.8
CVE-2022-23480

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux CRITICAL 9.8
CVE-2022-23478

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux CRITICAL 9.8
CVE-2022-23479

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux CRITICAL 9.8
CVE-2022-23468

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux CRITICAL 9.8
CVE-2022-23477

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux CRITICAL 10.0
CVE-2022-30123

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and Common…

Fix: 2.0.9.1 / 2.1.4.1+
Fix from $2,300 2022-12-05
Debian Linux CRITICAL 9.8
CVE-2022-36227

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the functio…

Fix: 3.6.2 / 8.2.12+
Fix from $2,300 2022-11-22
Debian Linux CRITICAL 9.8
CVE-2022-45062

In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

Fix: 4.16.4+
Fix from $2,300 2022-11-09
Debian Linux CRITICAL 9.8
CVE-2022-39353

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-form…

Fix: 0.6.0 / 0.7.7+
Fix from $2,300 2022-11-02
Debian Linux CRITICAL 9.8
CVE-2022-37454EPSS 6%

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute …

Fix: 1.0.5 / 3.7.16+
Fix from $2,300 2022-10-21
Debian Linux CRITICAL 9.8
CVE-2022-37601

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affect…

Fix: 1.4.1 / 2.0.3+
Fix from $2,300 2022-10-12
Debian Linux CRITICAL 9.8
CVE-2022-37616

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.j…

Fix: 0.7.6 / 0.8.3+
Fix from $2,300 2022-10-11
Debian Linux CRITICAL 9.8
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote c…

Fix: 2.7.1+
Fix from $2,300 2022-10-06
Logcheck CRITICAL 9.8
CVE-2017-20148

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck us…

Fix: after 1.3.23
Fix from $2,300 2022-09-20
Debian Linux CRITICAL 9.1
CVE-2022-37032

An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capabi…

Fix: 8.4+
Fix from $2,300 2022-09-19
Debian Linux CRITICAL 9.8
CVE-2020-22669

Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters an…

Patch available
Fix from $2,300 2022-09-02
Debian Linux CRITICAL 9.8
CVE-2022-37452

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

Fix: 4.95+
Fix from $2,300 2022-08-07
Debian Linux CRITICAL 9.8
CVE-2022-32292

In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in receiv…

Fix: after 1.41
Fix from $2,300 2022-08-03
Debian Linux CRITICAL 9.8
CVE-2020-7677

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and thi…

Fix: 3.3.1+
Fix from $2,300 2022-07-25
Debian Linux CRITICAL 9.8
CVE-2021-40874

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (…

Patch available
Fix from $2,300 2022-07-18
Debian Linux CRITICAL 9.1
CVE-2022-35409

An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid Clien…

Fix: 2.28.1 / 3.2.0+
Fix from $2,300 2022-07-15
Debian Linux CRITICAL 9.8
CVE-2022-31031

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.12.1
Fix from $2,300 2022-06-09
Debian Linux CRITICAL 9.8
CVE-2022-31799

Bottle before 0.12.20 mishandles errors during early request binding.

Fix: 0.12.20+
Fix from $2,300 2022-06-02
Debian Linux CRITICAL 9.8
CVE-2022-31003

Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `…

Fix: 1.13.8+
Fix from $2,300 2022-05-31
Dpkg CRITICAL 9.8
CVE-2022-1664

Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa…

Fix: 1.18.26 / 1.19.8+
Fix from $2,300 2022-05-26
Debian Linux CRITICAL 9.3
CVE-2022-1650

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

Fix: 1.1.1 / 2.0.2+
Fix from $2,300 2022-05-12
Debian Linux CRITICAL 9.8
CVE-2022-29155EPSS 64%

In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL s…

Fix: 2.5.12 / 2.6.2+
Fix from $2,300 2022-05-04
Debian Linux CRITICAL 9.8
CVE-2022-28044

Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.

Patch available
Fix from $2,300 2022-04-15