Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.8
CVE-2021-43305

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the L…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux HIGH 8.1
CVE-2021-42387

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit uns…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux HIGH 8.1
CVE-2021-42388

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit uns…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux MEDIUM 5.6
CVE-2022-23960

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage t…

Patch available
Fix from $1,600 2022-03-13
Debian Linux CRITICAL 9.8
CVE-2022-24754

PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stac…

Fix: after 2.12
Fix from $2,300 2022-03-11
Debian Linux MEDIUM 5.5
CVE-2022-0924

Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile lib…

Patch available
Fix from $1,600 2022-03-11
Debian Linux MEDIUM 5.5
CVE-2022-0909

Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libti…

Patch available
Fix from $1,600 2022-03-11
Debian Linux MEDIUM 5.5
CVE-2022-0908

Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could le…

Fix: after 4.3.0
Fix from $1,600 2022-03-11
Debian Linux MEDIUM 5.5
CVE-2022-0907

Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file…

Patch available
Fix from $1,600 2022-03-11
Debian Linux MEDIUM 5.4
CVE-2022-26874

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware…

Fix: 2.2.4+
Fix from $1,600 2022-03-11
Debian Linux HIGH 7.5
CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Fix: 2.12.6.1 / 2.13.2.1+
Fix from $1,950 2022-03-11
Debian Linux HIGH 7.0
CVE-2022-23036

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23037

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23038

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23039

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23040

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23041

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23042

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux MEDIUM 5.3
CVE-2022-26847

SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

Fix: 3.2.14 / 4.0.5+
Fix from $1,600 2022-03-10
Debian Linux HIGH 8.8
CVE-2022-26846

SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

Fix: 3.2.14 / 4.0.5+
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.5
CVE-2022-26662

An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.…

Fix: 5.0.12 / 5.0.46+
Fix from $1,950 2022-03-10
Debian Linux MEDIUM 6.5
CVE-2022-26661

An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tr…

Fix: 5.0.12 / 5.0.46+
Fix from $1,600 2022-03-10
Debian Linux HIGH 7.1
CVE-2022-0891

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bou…

Fix: after 4.3.0
Fix from $1,950 2022-03-10
Debian Linux MEDIUM 6.5
CVE-2022-0865

Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff …

Patch available
Fix from $1,600 2022-03-10
Debian Linux CRITICAL 9.1
CVE-2021-33293

Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.

Patch available
Fix from $2,300 2022-03-10
Debian Linux HIGH 7.4
CVE-2022-26505

A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.

Fix: 1.3.1+
Fix from $1,950 2022-03-06
Debian Linux CRITICAL 9.8
CVE-2022-26495

In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length …

Fix: 3.24+
Fix from $2,300 2022-03-06
Debian Linux CRITICAL 9.8
CVE-2022-26496

In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by…

Fix: 3.24+
Fix from $2,300 2022-03-06
Debian Linux MEDIUM 6.1
CVE-2021-20303

A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR …

Fix: 2.5.4+
Fix from $1,600 2022-03-04
Debian Linux MEDIUM 5.5
CVE-2021-20300

A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file th…

Fix: 2.5.4+
Fix from $1,600 2022-03-04