Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2022-3598

LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-servi…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 6.5
CVE-2022-3599

LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 6.5
CVE-2022-3626

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allo…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 6.5
CVE-2022-3627

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowi…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 6.5
CVE-2022-3597

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowi…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 5.5
CVE-2022-3570

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory acces…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux CRITICAL 9.8
CVE-2022-37454EPSS 5%

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute …

Fix: 1.0.5 / 3.7.16+
Fix from $2,300 2022-10-21
Debian Linux HIGH 7.5
CVE-2022-3517

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand func…

Fix: 3.0.5+
Fix from $1,950 2022-10-17
Debian Linux HIGH 8.8
CVE-2022-3550

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xk…

Fix: 21.1.6+
Fix from $1,950 2022-10-17
Debian Linux MEDIUM 6.5
CVE-2022-3551

A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of t…

Fix: 21.1.6+
Fix from $1,600 2022-10-17
Debian Linux HIGH 8.8
CVE-2022-42902

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input…

Fix: 2022.10+
Fix from $1,950 2022-10-13
Debian Linux HIGH 7.8
CVE-2022-42906

powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration…

Fix: 1.3.2+
Fix from $1,950 2022-10-13
Debian Linux HIGH 7.5
CVE-2021-36369

An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH …

Fix: after 2020.81
Fix from $1,950 2022-10-12
Debian Linux CRITICAL 9.8
CVE-2022-37601

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affect…

Fix: 1.4.1 / 2.0.3+
Fix from $2,300 2022-10-12
Debian Linux HIGH 7.5
CVE-2022-41404

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via …

Fix: 0.5.4+
Fix from $1,950 2022-10-11
Debian Linux MEDIUM 6.3
CVE-2022-3140EPSS 6%

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice…

Fix: 7.3.6+
Fix from $1,600 2022-10-11
Debian Linux HIGH 7.8
CVE-2022-20421

In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2022-10-11
Debian Linux HIGH 7.0
CVE-2022-20422

In emulation_proc_handler of armv8_deprecated.c, there is a possible way to corrupt memory due to a race condition. This could lead to local escalati…

Patch available
Fix from $1,950 2022-10-11
Debian Linux CRITICAL 9.8
CVE-2022-37616

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.j…

Fix: 0.7.6 / 0.8.3+
Fix from $2,300 2022-10-11
Debian Linux MEDIUM 6.5
CVE-2022-2929

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn l…

Fix: 4.1-esv+
Fix from $1,600 2022-10-07
Debian Linux MEDIUM 6.5
CVE-2022-2928

In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increa…

Fix: after 4.4.3
Fix from $1,600 2022-10-07
Debian Linux CRITICAL 9.8
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote c…

Fix: 2.7.1+
Fix from $2,300 2022-10-06
Debian Linux HIGH 7.5
CVE-2022-42003

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value d…

Fix: 2.12.7.1 / 2.13.3+
Fix from $1,950 2022-10-02
Debian Linux HIGH 7.5
CVE-2022-42004

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to …

Fix: 2.12.7.1 / 2.13.0+
Fix from $1,950 2022-10-02
Debian Linux HIGH 7.8
CVE-2022-1270

In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.

No fix yet
Fix from $1,950 2022-09-28
Debian Linux MEDIUM 6.1
CVE-2022-32166

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead acc…

Fix: after 2.5.0
Fix from $1,600 2022-09-28
Debian Linux HIGH 7.5
CVE-2022-38177

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to …

Fix: after 9.16.32
Fix from $1,950 2022-09-21
Debian Linux HIGH 7.5
CVE-2022-38178

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to …

Fix: after 9.16.32
Fix from $1,950 2022-09-21
Debian Linux MEDIUM 5.3
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denyin…

Fix: 9.16.33 / 9.18.7+
Fix from $1,600 2022-09-21
Logcheck CRITICAL 9.8
CVE-2017-20148

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck us…

Fix: after 1.3.23
Fix from $2,300 2022-09-20