Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-33912EPSS 10% libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated … Debian Linux 1.2.11+ Fix from $2,3002022-01-19 CRITICAL 9.8 CVE-2022-23221EPSS 65% H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FO… Debian Linux 2.0.206+ Fix from $2,3002022-01-19 CRITICAL 9.8 CVE-2022-23218 The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on t… Debian Linux 2.31+ Fix from $2,3002022-01-14 CRITICAL 9.8 CVE-2022-23219 The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on … Debian Linux 2.31+ Fix from $2,3002022-01-14 CRITICAL 9.8 CVE-2022-22822 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Debian Linux 2.4.3 / 3.1+ Fix from $2,3002022-01-10 CRITICAL 9.8 CVE-2022-22823 build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Debian Linux 2.4.3 / 3.1+ Fix from $2,3002022-01-10 CRITICAL 9.8 CVE-2022-22824 defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. Debian Linux 2.4.3 / 3.1+ Fix from $2,3002022-01-10 CRITICAL 9.8 CVE-2021-42392EPSS 63% The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack… Debian Linux after 2.0.204 Fix from $2,3002022-01-10 CRITICAL 9.1 CVE-2021-43845 PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data fi… Debian Linux after 2.11.1 Fix from $2,3002021-12-27 CRITICAL 9.8 CVE-2021-40393 An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a… Debian Linux No fix yet Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2021-40394 An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a… Debian Linux No fix yet Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2021-37706 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S… Debian Linux 16.8.0 / 16.24.1+ Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2021-44732 Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. Debian Linux 2.16.12 / 2.28.0+ Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-23450EPSS 30% All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. Debian Linux 1.17.0+ Fix from $2,3002021-12-17 CRITICAL 9.8 CVE-2021-43113EPSS 5% iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost… Debian Linux 7.1.17+ Fix from $2,3002021-12-15 CRITICAL 9.8 CVE-2021-44538 The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic… Debian Linux 1.6.0 / 1.9.7-sc1+ Fix from $2,3002021-12-14 CRITICAL 9.8 CVE-2021-44143 A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted ma… Debian Linux after 1.4.3 Fix from $2,3002021-11-22 CRITICAL 9.8 CVE-2021-40391 An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forke… Debian Linux No fix yet Fix from $2,3002021-11-19 CRITICAL 9.8 CVE-2021-3918 json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') Debian Linux 0.4.0+ Fix from $2,3002021-11-13 CRITICAL 9.8 CVE-2021-3907 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr… Debian Linux 1.3.0+ Fix from $2,3002021-11-11 CRITICAL 9.1 CVE-2021-43400 An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu… Debian Linux Patch available Fix from $2,3002021-11-04 CRITICAL 9.6 CVE-2021-3693 LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, thi… Debian Linux after 1.8.17 Fix from $2,3002021-08-23 CRITICAL 9.6 CVE-2021-3694 LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this fla… Debian Linux after 1.8.17 Fix from $2,3002021-08-23 CRITICAL 9.8 CVE-2021-38171 adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the sec… Debian Linux Patch available Fix from $2,3002021-08-21 CRITICAL 9.8 CVE-2021-38173 Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize… Debian Linux 0.31.2+ Fix from $2,3002021-08-07 CRITICAL 9.1 CVE-2021-35942 The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called… Debian Linux 2.31+ Fix from $2,3002021-07-22 CRITICAL 9.8 CVE-2021-33833 ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A … Debian Linux after 1.39 Fix from $2,3002021-06-09 CRITICAL 9.1 CVE-2020-36330 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this … Debian Linux 1.0.1 / 14.7+ Fix from $2,3002021-05-21 CRITICAL 9.8 CVE-2021-20204 A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This … Debian Linux Mitigation only Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2021-31870 An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer… Debian Linux 2.0.9+ Fix from $2,3002021-04-30