Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2021-20302

A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be process…

Fix: 2.5.4+
Fix from $1,600 2022-03-04
Debian Linux CRITICAL 9.8
CVE-2022-0730

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

No fix yet
Fix from $2,300 2022-03-03
Debian Linux HIGH 7.5
CVE-2022-21716

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is ab…

Fix: 22.2.0+
Fix from $1,950 2022-03-03
Debian Linux HIGH 7.5
CVE-2022-23648EPSS 27%

containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.1…

Fix: 1.4.13 / 1.5.10+
Fix from $1,950 2022-03-03
Debian Linux MEDIUM 6.5
CVE-2022-0577

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

Fix: 2.6.1+
Fix from $1,600 2022-03-02
Debian Linux HIGH 7.8
CVE-2022-0545

An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing…

Fix: 2.83.19 / 2.93.8+
Fix from $1,950 2022-02-24
Debian Linux MEDIUM 6.0
CVE-2021-3607

An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handl…

Fix: 6.1.0+
Fix from $1,600 2022-02-24
Debian Linux MEDIUM 6.0
CVE-2021-3608

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA…

Fix: 6.1.0+
Fix from $1,600 2022-02-24
Debian Linux MEDIUM 5.5
CVE-2022-0544

An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafte…

Fix: 2.83.19 / 2.93.8+
Fix from $1,600 2022-02-24
Debian Linux HIGH 8.8
CVE-2022-24407

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

Fix: after 2.1.27
Fix from $1,950 2022-02-24
Debian Linux MEDIUM 6.5
CVE-2022-24599

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak s…

No fix yet
Fix from $1,600 2022-02-24
Debian Linux CRITICAL 9.8
CVE-2022-23608

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.8.0 / 16.24.1+
Fix from $2,300 2022-02-22
Debian Linux HIGH 8.8
CVE-2021-44142EPSS 74%

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperabilit…

Mitigation only
Fix from $1,950 2022-02-21
Duck CRITICAL 9.8
CVE-2016-1239

duck before 0.10 did not properly handle loading of untrusted code from the current directory.

Fix: 0.10+
Fix from $2,300 2022-02-19
Debian Linux HIGH 8.8
CVE-2020-25722

Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause…

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-02-18
Debian Linux HIGH 8.1
CVE-2020-25717

A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…

Patch available
Fix from $1,950 2022-02-18
Debian Linux HIGH 7.2
CVE-2020-25719

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b…

Patch available
Fix from $1,950 2022-02-18
Debian Linux MEDIUM 5.9
CVE-2016-2124

A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w…

Patch available
Fix from $1,600 2022-02-18
Debian Linux CRITICAL 9.8
CVE-2022-25315

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

Fix: 2.4.5 / 3.1+
Fix from $2,300 2022-02-18
Debian Linux HIGH 7.5
CVE-2022-25314

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

Fix: 2.4.5 / 3.1+
Fix from $1,950 2022-02-18
Debian Linux MEDIUM 6.5
CVE-2022-25313

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Fix: 2.4.5 / 3.1+
Fix from $1,600 2022-02-18
Debian Linux CRITICAL 9.8
CVE-2021-43299

Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copi…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43300

Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is co…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43301

Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is …

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43303

Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an o…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.1
CVE-2021-43302

Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when t…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux HIGH 7.8
CVE-2021-3560 KEVEPSS 22%

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r…

Fix: 0.119+
Fix from $1,950 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2022-25235

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a c…

Fix: 2.4.5 / 3.1+
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2022-25236EPSS 36%

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

Fix: 2.4.5 / 3.1+
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-20001

It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions…

Fix: 2.12.16+
Fix from $2,300 2022-02-11