Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2022-23477

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux HIGH 7.8
CVE-2022-41325

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playl…

Fix: after 3.0.17.4
Fix from $1,950 2022-12-06
Debian Linux CRITICAL 10.0
CVE-2022-30123

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and Common…

Fix: 2.0.9.1 / 2.1.4.1+
Fix from $2,300 2022-12-05
Debian Linux HIGH 7.5
CVE-2022-30122

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

Fix: 2.0.9.1 / 2.1.4.1+
Fix from $1,950 2022-12-05
Debian Linux MEDIUM 6.1
CVE-2022-46391

AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

Fix: after 7.8
Fix from $1,600 2022-12-04
Debian Linux MEDIUM 6.5
CVE-2022-46338

g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writabl…

Patch available
Fix from $1,600 2022-11-30
Debian Linux HIGH 8.8
CVE-2022-45442

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4…

Fix: 2.2.3 / 3.0.4+
Fix from $1,950 2022-11-28
Debian Linux HIGH 7.8
CVE-2022-45939

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …

Fix: after 28.2
Fix from $1,950 2022-11-28
Debian Linux HIGH 7.5
CVE-2022-24999EPSS 15%

qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application becau…

Fix: 4.17.3 / 6.2.4+
Fix from $1,950 2022-11-26
Debian Linux HIGH 8.8
CVE-2022-44789

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution …

Fix: 1.3.2+
Fix from $1,950 2022-11-23
Debian Linux CRITICAL 9.8
CVE-2022-36227

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the functio…

Fix: 3.6.2 / 8.2.12+
Fix from $2,300 2022-11-22
Debian Linux MEDIUM 6.5
CVE-2022-44641

In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recur…

Fix: 2022.11+
Fix from $1,600 2022-11-18
Debian Linux HIGH 7.5
CVE-2022-41916

Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal…

Fix: 7.7.1+
Fix from $1,950 2022-11-15
Debian Linux HIGH 8.8
CVE-2022-3970

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getim…

Fix: 4.5.0 / 13.5+
Fix from $1,950 2022-11-13
Debian Linux HIGH 7.8
CVE-2022-45188

Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root…

Fix: after 3.1.13
Fix from $1,950 2022-11-12
Debian Linux CRITICAL 9.8
CVE-2022-45062

In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

Fix: 4.16.4+
Fix from $2,300 2022-11-09
Debian Linux HIGH 7.8
CVE-2022-39377

sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, all…

Fix: 12.6.1+
Fix from $1,950 2022-11-08
Debian Linux MEDIUM 6.5
CVE-2022-44792EPSS 52%

handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote…

Fix: after 5.9.3
Fix from $1,600 2022-11-07
Debian Linux MEDIUM 6.5
CVE-2022-44793EPSS 53%

handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a …

Fix: after 5.9.3
Fix from $1,600 2022-11-07
Debian Linux HIGH 7.8
CVE-2022-40284

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploi…

Fix: 2022.10.3+
Fix from $1,950 2022-11-06
Debian Linux HIGH 7.8
CVE-2021-34055

jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.

Patch available
Fix from $1,950 2022-11-04
Debian Linux HIGH 8.8
CVE-2022-44638

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflo…

Fix: 0.42.2+
Fix from $1,950 2022-11-03
Debian Linux CRITICAL 9.8
CVE-2022-39353

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-form…

Fix: 0.6.0 / 0.7.7+
Fix from $2,300 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43252

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability all…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43253

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulner…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43245

Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal<unsigned short> in sao.cc. This vulnerability allows attack…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43248

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred_avg_16_fallback in fallback-motion.cc. This vuln…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43249

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback<unsigned short> in fallback-motion.cc. This v…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43250

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fallback_16 in fallback-motion.cc. This vulnerability…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43239

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_chroma<unsigned short> in motion.cc. This vulnerability allows …

No fix yet
Fix from $1,600 2022-11-02