Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2022-0534

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malici…

Patch available
Fix from $1,600 2022-02-09
Debian Linux HIGH 7.5
CVE-2022-21712

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following…

Fix: 22.1.0+
Fix from $1,950 2022-02-07
Perm CRITICAL 9.8
CVE-2021-38172

perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.)

Patch available
Fix from $2,300 2022-02-05
Debian Linux MEDIUM 5.5
CVE-2021-4043

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

Fix: 1.1.0+
Fix from $1,600 2022-02-04
Debian Linux MEDIUM 5.3
CVE-2021-46671

options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client.

Fix: 0.7.5+
Fix from $1,600 2022-02-04
Debian Linux CRITICAL 9.8
CVE-2022-24300

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injectio…

Fix: 5.4.0+
Fix from $2,300 2022-02-02
Debian Linux MEDIUM 6.5
CVE-2022-24301

In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.

Fix: 5.4.0+
Fix from $1,600 2022-02-02
Debian Linux MEDIUM 6.5
CVE-2022-23607

treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq…

Fix: 22.1.0+
Fix from $1,600 2022-02-01
Debian Linux CRITICAL 9.1
CVE-2021-45079

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the ca…

Fix: 5.9.5+
Fix from $2,300 2022-01-31
Debian Linux MEDIUM 5.5
CVE-2022-24130

xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted te…

Fix: after 370
Fix from $1,600 2022-01-31
Debian Linux HIGH 7.8
CVE-2022-0392

Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.

Fix: 8.2.4218 / 12.6+
Fix from $1,950 2022-01-28
Debian Linux CRITICAL 9.1
CVE-2022-23096

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient He…

Fix: after 1.40
Fix from $2,300 2022-01-28
Debian Linux CRITICAL 9.1
CVE-2022-23097

An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.

Fix: after 1.40
Fix from $2,300 2022-01-28
Debian Linux HIGH 7.5
CVE-2022-23098

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

Fix: after 1.40
Fix from $1,950 2022-01-28
Debian Linux CRITICAL 9.1
CVE-2022-21722

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.11.1
Fix from $2,300 2022-01-27
Debian Linux CRITICAL 9.1
CVE-2022-21723

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.24.1 / 18.10.1+
Fix from $2,300 2022-01-27
Debian Linux HIGH 7.5
CVE-2022-23990

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

Fix: 2.4.4 / 3.1+
Fix from $1,950 2022-01-26
Debian Linux HIGH 7.8
CVE-2022-0368

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4217 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux MEDIUM 5.5
CVE-2021-22570

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file…

Fix: 3.15.0+
Fix from $1,600 2022-01-26
Debian Linux HIGH 7.8
CVE-2022-0361

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4215 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux HIGH 7.8
CVE-2022-0359

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4214 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux HIGH 7.8
CVE-2022-0351

Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.

Fix: 8.2 / 12.6+
Fix from $1,950 2022-01-25
Debian Linux CRITICAL 9.1
CVE-2021-3850

Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.

Fix: after 5.20.21
Fix from $2,300 2022-01-25
Debian Linux HIGH 7.8
CVE-2021-45845

The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted …

Patch available
Fix from $1,950 2022-01-25
Debian Linux HIGH 7.8
CVE-2021-45844

Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

Patch available
Fix from $1,950 2022-01-25
Debian Linux CRITICAL 9.8
CVE-2022-23852

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

Fix: 2.4.4 / 3.1+
Fix from $2,300 2022-01-24
Debian Linux HIGH 7.5
CVE-2022-23837EPSS 5%

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system,…

Fix: 5.2.10 / 6.4.0+
Fix from $1,950 2022-01-21
Debian Linux CRITICAL 9.8
CVE-2021-23518

The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create…

Fix: 1.1.0+
Fix from $2,300 2022-01-21
Debian Linux MEDIUM 5.5
CVE-2022-0319

Out-of-bounds Read in vim/vim prior to 8.2.

Fix: 8.2.4154 / 13.0+
Fix from $1,600 2022-01-21
Debian Linux CRITICAL 9.8
CVE-2022-0318

Heap-based Buffer Overflow in vim/vim prior to 8.2.

Fix: 8.2.4151 / 13.0+
Fix from $2,300 2022-01-21