Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2022-30293

In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platf…

Fix: after 2.36.0
Fix from $1,950 2022-05-06
Debian Linux CRITICAL 9.8
CVE-2022-29155EPSS 64%

In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL s…

Fix: 2.5.12 / 2.6.2+
Fix from $2,300 2022-05-04
Debian Linux HIGH 7.8
CVE-2021-42529

XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code exec…

Fix: after 2021.07
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.8
CVE-2021-42530

XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code exec…

Fix: after 2021.07
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.8
CVE-2021-42531

XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code exec…

Fix: after 2021.07
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.8
CVE-2021-42532

XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code exec…

Fix: after 2021.07
Fix from $1,950 2022-05-02
Debian Linux MEDIUM 5.5
CVE-2021-42528

XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated a…

Fix: after 2021.07
Fix from $1,600 2022-05-02
Debian Linux HIGH 7.8
CVE-2021-46790

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecat…

Fix: after 2021.8.22
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.5
CVE-2022-29970

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

Fix: 2.2.0+
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.5
CVE-2022-25647EPSS 12%

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal clas…

Fix: 2.8.9+
Fix from $1,950 2022-05-01
Debian Linux HIGH 7.8
CVE-2022-27239

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining…

Fix: 6.15+
Fix from $1,950 2022-04-27
Debian Linux HIGH 7.8
CVE-2022-1441

MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the fu…

Patch available
Fix from $1,950 2022-04-25
Debian Linux HIGH 7.5
CVE-2022-24792

PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit sys…

Fix: after 2.12
Fix from $1,950 2022-04-25
Debian Linux HIGH 7.8
CVE-2019-25059

Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

Fix: after 9.26
Fix from $1,950 2022-04-25
Debian Linux MEDIUM 5.3
CVE-2022-21496

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affec…

Fix: after 11.70.1
Fix from $1,600 2022-04-19
Debian Linux HIGH 7.5
CVE-2022-21476

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 17.0.2
Fix from $1,950 2022-04-19
Debian Linux HIGH 7.5
CVE-2022-21449EPSS 60%

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Patch available
Fix from $1,950 2022-04-19
Debian Linux MEDIUM 5.3
CVE-2022-21426

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…

Patch available
Fix from $1,600 2022-04-19
Debian Linux MEDIUM 5.3
CVE-2022-21434

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Patch available
Fix from $1,600 2022-04-19
Debian Linux HIGH 7.1
CVE-2022-29458

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo libra…

Fix: 6.3 / 13.0+
Fix from $1,950 2022-04-18
Debian Linux MEDIUM 5.5
CVE-2022-24859

PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In versions prior to 1.…

Fix: 1.27.5+
Fix from $1,600 2022-04-18
Debian Linux HIGH 7.8
CVE-2021-3624

There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be exe…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-35629

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-35630

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-35631

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-35632

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-28615

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-28616

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-28617

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux HIGH 8.8
CVE-2020-28618

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed fil…

No fix yet
Fix from $1,950 2022-04-18