Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2022-26651EPSS 7%

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escapi…

Fix: 16.25.2 / 18.11.2+
Fix from $2,300 2022-04-15
Debian Linux CRITICAL 9.1
CVE-2022-26499EPSS 8%

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces s…

Fix: 18.11.2+
Fix from $2,300 2022-04-15
Debian Linux CRITICAL 9.8
CVE-2022-24786

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI…

Fix: after 2.12
Fix from $2,300 2022-04-06
Debian Linux CRITICAL 9.8
CVE-2022-24754

PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stac…

Fix: after 2.12
Fix from $2,300 2022-03-11
Debian Linux CRITICAL 9.1
CVE-2021-33293

Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.

Patch available
Fix from $2,300 2022-03-10
Debian Linux CRITICAL 9.8
CVE-2022-26495

In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length …

Fix: 3.24+
Fix from $2,300 2022-03-06
Debian Linux CRITICAL 9.8
CVE-2022-26496

In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by…

Fix: 3.24+
Fix from $2,300 2022-03-06
Debian Linux CRITICAL 9.8
CVE-2022-0730

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

No fix yet
Fix from $2,300 2022-03-03
Debian Linux CRITICAL 9.8
CVE-2022-23608

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.8.0 / 16.24.1+
Fix from $2,300 2022-02-22
Duck CRITICAL 9.8
CVE-2016-1239

duck before 0.10 did not properly handle loading of untrusted code from the current directory.

Fix: 0.10+
Fix from $2,300 2022-02-19
Debian Linux CRITICAL 9.8
CVE-2022-25315

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

Fix: 2.4.5 / 3.1+
Fix from $2,300 2022-02-18
Debian Linux CRITICAL 9.8
CVE-2021-43299

Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copi…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43300

Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is co…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43301

Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is …

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43303

Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an o…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.1
CVE-2021-43302

Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when t…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2022-25235

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a c…

Fix: 2.4.5 / 3.1+
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2022-25236EPSS 36%

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

Fix: 2.4.5 / 3.1+
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-20001

It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions…

Fix: 2.12.16+
Fix from $2,300 2022-02-11
Perm CRITICAL 9.8
CVE-2021-38172

perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.)

Patch available
Fix from $2,300 2022-02-05
Debian Linux CRITICAL 9.8
CVE-2022-24300

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injectio…

Fix: 5.4.0+
Fix from $2,300 2022-02-02
Debian Linux CRITICAL 9.1
CVE-2021-45079

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the ca…

Fix: 5.9.5+
Fix from $2,300 2022-01-31
Debian Linux CRITICAL 9.1
CVE-2022-23096

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient He…

Fix: after 1.40
Fix from $2,300 2022-01-28
Debian Linux CRITICAL 9.1
CVE-2022-23097

An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.

Fix: after 1.40
Fix from $2,300 2022-01-28
Debian Linux CRITICAL 9.1
CVE-2022-21722

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.11.1
Fix from $2,300 2022-01-27
Debian Linux CRITICAL 9.1
CVE-2022-21723

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.24.1 / 18.10.1+
Fix from $2,300 2022-01-27
Debian Linux CRITICAL 9.1
CVE-2021-3850

Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.

Fix: after 5.20.21
Fix from $2,300 2022-01-25
Debian Linux CRITICAL 9.8
CVE-2022-23852

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

Fix: 2.4.4 / 3.1+
Fix from $2,300 2022-01-24
Debian Linux CRITICAL 9.8
CVE-2021-23518

The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create…

Fix: 1.1.0+
Fix from $2,300 2022-01-21
Debian Linux CRITICAL 9.8
CVE-2022-0318

Heap-based Buffer Overflow in vim/vim prior to 8.2.

Fix: 8.2.4151 / 13.0+
Fix from $2,300 2022-01-21