Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2021-33912EPSS 10%

libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated …

Fix: 1.2.11+
Fix from $2,300 2022-01-19
Debian Linux CRITICAL 9.8
CVE-2022-23221EPSS 65%

H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FO…

Fix: 2.0.206+
Fix from $2,300 2022-01-19
Debian Linux CRITICAL 9.8
CVE-2022-23218

The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on t…

Fix: 2.31+
Fix from $2,300 2022-01-14
Debian Linux CRITICAL 9.8
CVE-2022-23219

The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on …

Fix: 2.31+
Fix from $2,300 2022-01-14
Debian Linux CRITICAL 9.8
CVE-2022-22822

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22823

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22824

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2021-42392EPSS 63%

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack…

Fix: after 2.0.204
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.1
CVE-2021-43845

PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data fi…

Fix: after 2.11.1
Fix from $2,300 2021-12-27
Debian Linux CRITICAL 9.8
CVE-2021-40393

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…

No fix yet
Fix from $2,300 2021-12-22
Debian Linux CRITICAL 9.8
CVE-2021-40394

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…

No fix yet
Fix from $2,300 2021-12-22
Debian Linux CRITICAL 9.8
CVE-2021-37706

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.8.0 / 16.24.1+
Fix from $2,300 2021-12-22
Debian Linux CRITICAL 9.8
CVE-2021-44732

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

Fix: 2.16.12 / 2.28.0+
Fix from $2,300 2021-12-20
Debian Linux CRITICAL 9.8
CVE-2021-23450EPSS 30%

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

Fix: 1.17.0+
Fix from $2,300 2021-12-17
Debian Linux CRITICAL 9.8
CVE-2021-43113EPSS 5%

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost…

Fix: 7.1.17+
Fix from $2,300 2021-12-15
Debian Linux CRITICAL 9.8
CVE-2021-44538

The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic…

Fix: 1.6.0 / 1.9.7-sc1+
Fix from $2,300 2021-12-14
Debian Linux CRITICAL 9.8
CVE-2021-44143

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted ma…

Fix: after 1.4.3
Fix from $2,300 2021-11-22
Debian Linux CRITICAL 9.8
CVE-2021-40391

An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forke…

No fix yet
Fix from $2,300 2021-11-19
Debian Linux CRITICAL 9.8
CVE-2021-3918

json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Fix: 0.4.0+
Fix from $2,300 2021-11-13
Debian Linux CRITICAL 9.8
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…

Fix: 1.3.0+
Fix from $2,300 2021-11-11
Debian Linux CRITICAL 9.1
CVE-2021-43400

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…

Patch available
Fix from $2,300 2021-11-04
Debian Linux CRITICAL 9.6
CVE-2021-3693

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, thi…

Fix: after 1.8.17
Fix from $2,300 2021-08-23
Debian Linux CRITICAL 9.6
CVE-2021-3694

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this fla…

Fix: after 1.8.17
Fix from $2,300 2021-08-23
Debian Linux CRITICAL 9.8
CVE-2021-38171

adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the sec…

Patch available
Fix from $2,300 2021-08-21
Debian Linux CRITICAL 9.8
CVE-2021-38173

Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize…

Fix: 0.31.2+
Fix from $2,300 2021-08-07
Debian Linux CRITICAL 9.1
CVE-2021-35942

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called…

Fix: 2.31+
Fix from $2,300 2021-07-22
Debian Linux CRITICAL 9.8
CVE-2021-33833

ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A …

Fix: after 1.39
Fix from $2,300 2021-06-09
Debian Linux CRITICAL 9.1
CVE-2020-36330

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this …

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Debian Linux CRITICAL 9.8
CVE-2021-20204

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This …

Mitigation only
Fix from $2,300 2021-05-06
Debian Linux CRITICAL 9.8
CVE-2021-31870

An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer…

Fix: 2.0.9+
Fix from $2,300 2021-04-30