Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2022-2126

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.5123 / 11.7+
Fix from $1,950 2022-06-19
Debian Linux HIGH 7.8
CVE-2022-2124

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.5120 / 11.7+
Fix from $1,950 2022-06-19
Debian Linux HIGH 7.5
CVE-2022-31291

An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.

Patch available
Fix from $1,950 2022-06-16
Debian Linux HIGH 8.8
CVE-2022-32278

XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.

Fix: 4.16.4 / 4.17.2+
Fix from $1,950 2022-06-13
Debian Linux CRITICAL 9.8
CVE-2022-31031

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.12.1
Fix from $2,300 2022-06-09
Debian Linux MEDIUM 5.5
CVE-2022-31030

containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause th…

Fix: 1.5.13 / 1.6.6+
Fix from $1,600 2022-06-09
Debian Linux HIGH 8.8
CVE-2019-9971

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tc…

No fix yet
Fix from $1,950 2022-06-07
Debian Linux HIGH 8.8
CVE-2019-9972

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the …

No fix yet
Fix from $1,950 2022-06-07
Debian Linux CRITICAL 9.8
CVE-2022-31799

Bottle before 0.12.20 mishandles errors during early request binding.

Fix: 0.12.20+
Fix from $2,300 2022-06-02
Debian Linux MEDIUM 5.9
CVE-2022-26491

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server…

Fix: 2.14.9+
Fix from $1,600 2022-06-02
Debian Linux HIGH 7.8
CVE-2022-1968

Use After Free in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.5050 / 13.0+
Fix from $1,950 2022-06-02
Debian Linux CRITICAL 9.8
CVE-2022-31003

Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `…

Fix: 1.13.8+
Fix from $2,300 2022-05-31
Debian Linux HIGH 7.5
CVE-2022-31001

Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil s…

Fix: 1.13.8+
Fix from $1,950 2022-05-31
Debian Linux HIGH 7.5
CVE-2022-31002

Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil s…

Fix: 1.13.8+
Fix from $1,950 2022-05-31
Debian Linux MEDIUM 6.7
CVE-2022-26691

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big …

Fix: 2.4.2 / 10.15.7+
Fix from $1,600 2022-05-26
Debian Linux HIGH 7.8
CVE-2022-30789

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.

Fix: after 2021.8.22
Fix from $1,950 2022-05-26
Debian Linux HIGH 7.8
CVE-2022-30784

A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.

Fix: after 2021.8.22
Fix from $1,950 2022-05-26
Dpkg CRITICAL 9.8
CVE-2022-1664

Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa…

Fix: 1.18.26 / 1.19.8+
Fix from $2,300 2022-05-26
Debian Linux HIGH 8.8
CVE-2022-29221

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.…

Fix: 3.1.45 / 4.1.1+
Fix from $1,950 2022-05-24
Debian Linux HIGH 7.8
CVE-2022-1785

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

Fix: 8.2.4977+
Fix from $1,950 2022-05-19
Debian Linux MEDIUM 5.5
CVE-2022-30974

compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.

Fix: after 1.2.0
Fix from $1,600 2022-05-18
Debian Linux MEDIUM 5.5
CVE-2022-30975

In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.

Fix: after 1.2.0
Fix from $1,600 2022-05-18
Debian Linux HIGH 7.8
CVE-2022-30688

needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anch…

Fix: 3.6+
Fix from $1,950 2022-05-17
Debian Linux MEDIUM 5.5
CVE-2022-21151

Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially …

Mitigation only
Fix from $1,600 2022-05-12
Debian Linux CRITICAL 9.3
CVE-2022-1650

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

Fix: 1.1.1 / 2.0.2+
Fix from $2,300 2022-05-12
Debian Linux HIGH 7.8
CVE-2022-1621

Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Byp…

Fix: 8.2.4919 / 13.0+
Fix from $1,950 2022-05-10
Debian Linux MEDIUM 5.5
CVE-2022-27114

There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large …

Patch available
Fix from $1,600 2022-05-09
Debian Linux HIGH 7.5
CVE-2022-30333 KEVEPSS 99%

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …

Fix: 6.12+
Fix from $1,950 2022-05-09
Debian Linux HIGH 7.8
CVE-2022-28463

ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.

Fix: 6.9.12-44 / 7.1.0-29+
Fix from $1,950 2022-05-08
Debian Linux HIGH 8.1
CVE-2018-25033

ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh…

Fix: after 0.98.4
Fix from $1,950 2022-05-08