Vulnerability index

Browse CVEs

214 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux HIGH 7.8
CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice…

Fix: 24.8.5.1 / 25.2.1.1+
Fix from $1,950 2025-03-04
Debian Linux CRITICAL 9.8
CVE-2024-47175EPSS 64%

CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFrom…

Fix: after 2.0.0
Fix from $2,300 2024-09-26
Debian Linux MEDIUM 5.0
CVE-2023-35936

Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.1…

Fix: 3.1.4+
Fix from $1,600 2023-07-05
Debian Linux CRITICAL 9.8
CVE-2022-39353

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-form…

Fix: 0.6.0 / 0.7.7+
Fix from $2,300 2022-11-02
Debian Linux MEDIUM 6.3
CVE-2022-3140EPSS 6%

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice…

Fix: 7.3.6+
Fix from $1,600 2022-10-11
Debian Linux HIGH 7.8
CVE-2022-30789

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.

Fix: after 2021.8.22
Fix from $1,950 2022-05-26
Debian Linux HIGH 7.8
CVE-2022-30784

A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.

Fix: after 2021.8.22
Fix from $1,950 2022-05-26
Debian Linux HIGH 7.8
CVE-2021-3624

There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be exe…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux MEDIUM 5.5
CVE-2021-20302

A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be process…

Fix: 2.5.4+
Fix from $1,600 2022-03-04
Debian Linux HIGH 8.1
CVE-2020-25717

A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…

Patch available
Fix from $1,950 2022-02-18
Debian Linux HIGH 7.5
CVE-2022-20698

A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allo…

Fix: 0.103.5 / 0.104.2+
Fix from $1,950 2022-01-14
Debian Linux HIGH 8.8
CVE-2021-21408

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.…

Fix: 3.1.43 / 4.0.3+
Fix from $1,950 2022-01-10
Debian Linux MEDIUM 6.5
CVE-2021-3911

If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.

Fix: 1.3.0+
Fix from $1,600 2021-11-11
Debian Linux CRITICAL 9.8
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…

Fix: 1.3.0+
Fix from $2,300 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3910

OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).

Fix: 1.4.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.8
CVE-2021-41133

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak …

Fix: 1.8.2 / 1.10.4+
Fix from $1,950 2021-10-08
Debian Linux HIGH 7.8
CVE-2021-39255

A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39256

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39258

A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39259

A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39260

A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39261

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39262

A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39263

A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-33287

In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur …

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39251

A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39252

A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39253

A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39254

A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NT…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-35268

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07