Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.1
CVE-2022-37032

An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capabi…

Fix: 8.4+
Fix from $2,300 2022-09-19
Debian Linux HIGH 7.5
CVE-2022-28203

A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requestin…

Fix: 1.35.6 / 1.36.4+
Fix from $1,950 2022-09-19
Debian Linux HIGH 7.5
CVE-2022-40149

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl…

Fix: after 1.4.0
Fix from $1,950 2022-09-16
Debian Linux HIGH 7.5
CVE-2022-40150

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl…

Fix: after 1.4.0
Fix from $1,950 2022-09-16
Debian Linux MEDIUM 5.5
CVE-2022-38850

The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c.

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38851

Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This aff…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38855

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects m…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38858

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38860

Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder.…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38861

The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38863

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and …

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38864

Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencod…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38865

Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects …

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38866

Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38…

Mitigation only
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.4
CVE-2018-25047

In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that coul…

Fix: 3.1.47 / 4.2.1+
Fix from $1,600 2022-09-15
Debian Linux HIGH 8.1
CVE-2022-40674

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

Fix: 2.4.9+
Fix from $1,950 2022-09-14
Debian Linux HIGH 7.5
CVE-2022-37797

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It lead…

No fix yet
Fix from $1,950 2022-09-12
Debian Linux MEDIUM 6.5
CVE-2022-38266

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a craft…

Fix: 1.80.0+
Fix from $1,600 2022-09-09
Debian Linux HIGH 7.5
CVE-2022-40023

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin…

Fix: 1.2.2+
Fix from $1,950 2022-09-07
Debian Linux HIGH 7.8
CVE-2022-3134

Use After Free in GitHub repository vim/vim prior to 9.0.0389.

Fix: 9.0.0389+
Fix from $1,950 2022-09-06
Debian Linux HIGH 7.8
CVE-2022-2735

A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between…

Fix: after 0.11.3
Fix from $1,950 2022-09-06
Debian Linux MEDIUM 6.5
CVE-2022-38749

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux MEDIUM 6.5
CVE-2022-38751

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux MEDIUM 5.5
CVE-2022-38750

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux HIGH 8.8
CVE-2022-3008

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…

Fix: 2.6.0+
Fix from $1,950 2022-09-05
Debian Linux HIGH 7.5
CVE-2020-29260

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

Patch available
Fix from $1,950 2022-09-02
Debian Linux CRITICAL 9.8
CVE-2020-22669

Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters an…

Patch available
Fix from $2,300 2022-09-02
Debian Linux MEDIUM 5.5
CVE-2020-35530

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggere…

Patch available
Fix from $1,600 2022-09-01
Debian Linux MEDIUM 5.5
CVE-2020-35531

In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data…

Patch available
Fix from $1,600 2022-09-01
Debian Linux MEDIUM 5.5
CVE-2020-35532

In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be t…

Patch available
Fix from $1,600 2022-09-01