Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2022-28044

Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.

Patch available
Fix from $2,300 2022-04-15
Debian Linux CRITICAL 9.8
CVE-2022-26651EPSS 7%

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escapi…

Fix: 16.25.2 / 18.11.2+
Fix from $2,300 2022-04-15
Debian Linux CRITICAL 9.1
CVE-2022-26499EPSS 8%

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces s…

Fix: 18.11.2+
Fix from $2,300 2022-04-15
Debian Linux HIGH 7.5
CVE-2022-26498EPSS 16%

An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files cou…

Fix: 18.11.2+
Fix from $1,950 2022-04-15
Debian Linux MEDIUM 5.3
CVE-2022-1328

Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line

Fix: 2.2.3+
Fix from $1,600 2022-04-14
Debian Linux HIGH 7.5
CVE-2022-24793

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.12 and prior affects app…

Fix: after 2.12
Fix from $1,950 2022-04-06
Debian Linux CRITICAL 9.8
CVE-2022-24786

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI…

Fix: after 2.12
Fix from $2,300 2022-04-06
Debian Linux HIGH 8.8
CVE-2022-26110

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon…

Fix: 8.8.16 / 9.0.10+
Fix from $1,950 2022-04-06
Debian Linux HIGH 7.8
CVE-2022-26358

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vuln…

Patch available
Fix from $1,950 2022-04-05
Debian Linux HIGH 7.8
CVE-2022-26359

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vuln…

Patch available
Fix from $1,950 2022-04-05
Debian Linux HIGH 7.8
CVE-2022-26360

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vuln…

Patch available
Fix from $1,950 2022-04-05
Debian Linux HIGH 7.8
CVE-2022-26361

IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vuln…

Patch available
Fix from $1,950 2022-04-05
Debian Linux HIGH 7.0
CVE-2022-26357

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associat…

Fix: 4.12.0 / 4.16.0+
Fix from $1,950 2022-04-05
Debian Linux MEDIUM 5.6
CVE-2022-26356

Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was nam…

Fix: 4.12.0 / 4.14.0+
Fix from $1,600 2022-04-05
Debian Linux HIGH 7.5
CVE-2021-43008EPSS 14%

Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote …

Fix: after 4.6.2
Fix from $1,950 2022-04-05
Debian Linux HIGH 8.1
CVE-2022-24801

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, l…

Fix: 22.4.0+
Fix from $1,950 2022-04-04
Debian Linux HIGH 7.5
CVE-2022-24763

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulne…

Fix: 2.13+
Fix from $1,950 2022-03-30
Debian Linux MEDIUM 5.5
CVE-2022-26291

lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vul…

Patch available
Fix from $1,600 2022-03-28
Debian Linux HIGH 8.8
CVE-2022-1049

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to logi…

Fix: after 0.11.2
Fix from $1,950 2022-03-25
Debian Linux MEDIUM 6.5
CVE-2021-3582

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due…

Fix: 2.17.2+
Fix from $1,600 2022-03-25
Debian Linux HIGH 7.5
CVE-2021-43666

A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.

Fix: after 3.0.0
Fix from $1,950 2022-03-24
Debian Linux HIGH 7.1
CVE-2021-4156

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricki…

Patch available
Fix from $1,950 2022-03-23
Debian Linux HIGH 7.5
CVE-2021-3748

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct acc…

Fix: 6.2.0+
Fix from $1,950 2022-03-23
Debian Linux HIGH 7.5
CVE-2022-24764

PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability …

Fix: after 2.12
Fix from $1,950 2022-03-22
Debian Linux MEDIUM 5.9
CVE-2022-24302

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information …

Fix: 2.10.1+
Fix from $1,600 2022-03-17
Debian Linux HIGH 7.5
CVE-2022-24761

Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not prope…

Fix: 2.1.1+
Fix from $1,950 2022-03-17
Debian Linux HIGH 7.5
CVE-2022-26353

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the c…

Patch available
Fix from $1,950 2022-03-16
Debian Linux HIGH 7.0
CVE-2021-39713

Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

Patch available
Fix from $1,950 2022-03-16
Debian Linux HIGH 7.5
CVE-2021-20299

A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer der…

Fix: 2.5.4+
Fix from $1,950 2022-03-16
Debian Linux HIGH 8.8
CVE-2021-43304

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the L…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14