Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2020-7677

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and thi…

Fix: 3.3.1+
Fix from $2,300 2022-07-25
Debian Linux HIGH 8.1
CVE-2022-31163

TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as …

Fix: 0.3.61 / 1.2.10+
Fix from $1,950 2022-07-22
Debian Linux HIGH 7.5
CVE-2021-46828

In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mis…

Fix: 1.3.3+
Fix from $1,950 2022-07-20
Debian Linux HIGH 7.8
CVE-2022-1924

DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which…

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 7.8
CVE-2022-1925

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_…

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 7.8
CVE-2022-2122

DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a se…

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 7.8
CVE-2022-1920

Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. …

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 7.8
CVE-2022-1921

Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary …

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 7.8
CVE-2022-1922

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data fu…

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 7.8
CVE-2022-1923

DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function whi…

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 8.1
CVE-2022-2469

GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client

Fix: 2.0.1+
Fix from $1,950 2022-07-19
Debian Linux CRITICAL 9.8
CVE-2021-40874

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (…

Patch available
Fix from $2,300 2022-07-18
Debian Linux HIGH 7.5
CVE-2020-16093

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backend…

Fix: after 2.0.8
Fix from $1,950 2022-07-18
Debian Linux MEDIUM 6.5
CVE-2021-46784

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing l…

Fix: 5.6+
Fix from $1,600 2022-07-17
Debian Linux HIGH 8.8
CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver …

Fix: 2.4.0+
Fix from $1,950 2022-07-17
Debian Linux CRITICAL 9.1
CVE-2022-35409

An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid Clien…

Fix: 2.28.1 / 3.2.0+
Fix from $2,300 2022-07-15
Debian Linux MEDIUM 6.5
CVE-2022-23825

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

Mitigation only
Fix from $1,600 2022-07-14
Debian Linux MEDIUM 6.5
CVE-2022-29900

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent condi…

Mitigation only
Fix from $1,600 2022-07-12
Debian Linux HIGH 8.8
CVE-2022-35414

softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE…

Fix: after 7.0.0
Fix from $1,950 2022-07-11
Debian Linux HIGH 7.5
CVE-2022-35410

mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affect…

Fix: 0.13.0+
Fix from $1,950 2022-07-08
Debian Linux HIGH 7.5
CVE-2022-2048

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properl…

Fix: 2.263 / 2.361.1+
Fix from $1,950 2022-07-07
Debian Linux HIGH 7.7
CVE-2022-31090

Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handle…

Fix: 6.5.8 / 7.4.5+
Fix from $1,950 2022-06-27
Debian Linux HIGH 7.7
CVE-2022-31091

Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a r…

Fix: 6.5.8 / 7.4.5+
Fix from $1,950 2022-06-27
Debian Linux HIGH 8.8
CVE-2022-31086

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux HIGH 8.1
CVE-2022-31084

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux HIGH 7.8
CVE-2022-31087

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux MEDIUM 6.5
CVE-2022-31081

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploite…

Fix: 6.15+
Fix from $1,600 2022-06-27
Debian Linux MEDIUM 6.1
CVE-2022-31085

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,600 2022-06-27
Debian Linux MEDIUM 5.3
CVE-2022-31088

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,600 2022-06-27
Debian Linux HIGH 7.8
CVE-2022-1720

Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, m…

Fix: 8.2.4956 / 11.7+
Fix from $1,950 2022-06-20