Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.8
CVE-2023-26314

The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associ…

Mitigation only
Fix from $1,950 2023-02-22
Debian Linux MEDIUM 6.5
CVE-2023-23009

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selec…

Patch available
Fix from $1,600 2023-02-21
Debian Linux CRITICAL 9.8
CVE-2022-48337

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …

Fix: after 28.2
Fix from $2,300 2023-02-20
Debian Linux CRITICAL 9.1
CVE-2023-25725EPSS 5%

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." …

Fix: 2.0.31 / 2.2.29+
Fix from $2,300 2023-02-14
Debian Linux HIGH 7.8
CVE-2023-0770

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.

Fix: 2.2.0+
Fix from $1,950 2023-02-09
Debian Linux HIGH 7.0
CVE-2023-0266 KEV

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be u…

Fix: 4.14.303 / 4.19.270+
Fix from $1,950 2023-01-30
Debian Linux MEDIUM 5.7
CVE-2022-47951

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and …

Fix: 20.0.2 / 23.0.1+
Fix from $1,600 2023-01-26
Debian Linux MEDIUM 5.5
CVE-2022-48281

processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF…

Fix: after 4.5.0
Fix from $1,600 2023-01-23
Debian Linux HIGH 7.5
CVE-2023-24038

The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain …

Fix: after 1.06
Fix from $1,950 2023-01-21
Debian Linux HIGH 7.5
CVE-2023-24021

Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on…

Fix: 2.9.7+
Fix from $1,950 2023-01-20
Debian Linux HIGH 7.5
CVE-2022-48279

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE…

Fix: 2.9.6 / 3.0.8+
Fix from $1,950 2023-01-20
Debian Linux HIGH 7.8
CVE-2023-22809EPSS 55%

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VIS…

Fix: 1.9.12 / 13.4+
Fix from $1,950 2023-01-18
Debian Linux MEDIUM 6.5
CVE-2022-47950

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may…

Fix: 2.28.1 / 2.29.2+
Fix from $1,600 2023-01-18
Debian Linux HIGH 8.0
CVE-2022-46648

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con…

Fix: 1.13.0+
Fix from $1,950 2023-01-17
Debian Linux HIGH 8.0
CVE-2022-47318

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con…

Fix: 1.13.0+
Fix from $1,950 2023-01-17
Debian Linux MEDIUM 6.5
CVE-2023-23589

The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka …

Fix: 0.4.7.13+
Fix from $1,600 2023-01-14
Debian Linux MEDIUM 5.3
CVE-2022-3341

A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because th…

Fix: 5.0.3+
Fix from $1,600 2023-01-12
Debian Linux CRITICAL 9.8
CVE-2022-4338

An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

Fix: 2.13.10 / 2.14.8+
Fix from $2,300 2023-01-10
Debian Linux CRITICAL 9.8
CVE-2022-4337

An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

Fix: 2.13.10 / 2.14.8+
Fix from $2,300 2023-01-10
Debian Linux HIGH 7.8
CVE-2022-47655

Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>

No fix yet
Fix from $1,950 2023-01-05
Debian Linux HIGH 8.1
CVE-2020-10650

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via igni…

Fix: 2.9.10.4+
Fix from $1,950 2022-12-26
Debian Linux HIGH 8.1
CVE-2022-43597

Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A spec…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux HIGH 8.1
CVE-2022-43598

Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A spec…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux HIGH 8.1
CVE-2022-43599

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafte…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux HIGH 8.1
CVE-2022-43600

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafte…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux HIGH 8.1
CVE-2022-43601

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafte…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux HIGH 8.1
CVE-2022-43602

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafte…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux HIGH 7.5
CVE-2022-41999

A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A sp…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux MEDIUM 5.9
CVE-2022-43592

An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially craft…

No fix yet
Fix from $1,600 2022-12-22
Debian Linux MEDIUM 5.9
CVE-2022-43593

A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted Ima…

No fix yet
Fix from $1,600 2022-12-22