Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.3
CVE-2023-26049

Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookie…

Fix: 9.4.51 / 10.0.14+
Fix from $1,600 2023-04-18
Debian Linux MEDIUM 5.9
CVE-2023-21967

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affe…

Fix: 8+
Fix from $1,600 2023-04-18
Debian Linux MEDIUM 5.9
CVE-2023-21954

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are a…

Fix: 8+
Fix from $1,600 2023-04-18
Debian Linux MEDIUM 5.3
CVE-2023-21939

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are aff…

Fix: 8+
Fix from $1,600 2023-04-18
Debian Linux HIGH 7.4
CVE-2023-21930

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affe…

Fix: 8+
Fix from $1,950 2023-04-18
Debian Linux HIGH 8.2
CVE-2023-1668

A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying …

Fix: 2.13.11 / 2.14.9+
Fix from $1,950 2023-04-10
Debian Linux MEDIUM 6.5
CVE-2023-29415

An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does n…

Fix: 1.3.0+
Fix from $1,600 2023-04-06
Debian Linux CRITICAL 9.8
CVE-2023-28879EPSS 6%

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in…

Fix: 10.01.0+
Fix from $2,300 2023-03-31
Debian Linux CRITICAL 9.8
CVE-2022-23121EPSS 9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-23122

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-23123

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-23124

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-23125

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-0194

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux HIGH 7.8
CVE-2023-0386 KEVEPSS 8%

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s…

Fix: 5.15.91 / 6.1.9+
Fix from $1,950 2023-03-22
Debian Linux HIGH 8.6
CVE-2022-42333

x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c…

Fix: after 4.17.0
Fix from $1,950 2023-03-21
Debian Linux MEDIUM 6.5
CVE-2022-42334

x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c…

Fix: after 4.17.0
Fix from $1,600 2023-03-21
Debian Linux HIGH 7.8
CVE-2022-42332

x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP)…

Mitigation only
Fix from $1,950 2023-03-21
Debian Linux MEDIUM 6.0
CVE-2023-0330

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like st…

Fix: 7.2.3+
Fix from $1,600 2023-03-06
Debmany HIGH 7.8
CVE-2023-27635

debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is…

Mitigation only
Fix from $1,950 2023-03-05
Debian Linux HIGH 7.8
CVE-2023-26604

systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "sys…

Fix: 246.7+
Fix from $1,950 2023-03-03
Debian Linux HIGH 7.8
CVE-2023-25221

Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc.

Patch available
Fix from $1,950 2023-03-01
Debian Linux MEDIUM 6.5
CVE-2023-24751

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to …

Patch available
Fix from $1,600 2023-03-01
Debian Linux MEDIUM 5.5
CVE-2023-24752

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulne…

Patch available
Fix from $1,600 2023-03-01
Debian Linux MEDIUM 5.5
CVE-2023-24754

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vuln…

Patch available
Fix from $1,600 2023-03-01
Debian Linux MEDIUM 5.5
CVE-2023-24755

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulner…

Patch available
Fix from $1,600 2023-03-01
Debian Linux MEDIUM 5.5
CVE-2023-24756

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulner…

Patch available
Fix from $1,600 2023-03-01
Debian Linux MEDIUM 5.5
CVE-2023-24757

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vul…

Patch available
Fix from $1,600 2023-03-01
Debian Linux MEDIUM 5.5
CVE-2023-24758

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vuln…

Patch available
Fix from $1,600 2023-03-01
Debian Linux CRITICAL 9.8
CVE-2023-27372EPSS 100%

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Fix: 3.2.18 / 4.0.10+
Fix from $2,300 2023-02-28