Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2021-36411

An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength…

No fix yet
Fix from $1,600 2022-01-10
Debian Linux MEDIUM 5.5
CVE-2021-36408

An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.

No fix yet
Fix from $1,600 2022-01-10
Debian Linux MEDIUM 6.5
CVE-2021-35452

An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.

No fix yet
Fix from $1,600 2022-01-10
Debian Linux HIGH 8.8
CVE-2021-29454

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.…

Fix: 3.1.42 / 4.0.2+
Fix from $1,950 2022-01-10
Debian Linux HIGH 8.8
CVE-2021-21408

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.…

Fix: 3.1.43 / 4.0.3+
Fix from $1,950 2022-01-10
Debian Linux MEDIUM 5.5
CVE-2022-22844

LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of th…

No fix yet
Fix from $1,600 2022-01-10
Debian Linux HIGH 8.8
CVE-2022-22826

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux HIGH 8.8
CVE-2022-22827

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22822

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22823

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22824

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux HIGH 8.8
CVE-2022-22825

lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux HIGH 7.8
CVE-2021-43579EPSS 7%

A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linki…

Fix: after 1.9.13
Fix from $1,950 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2021-42392EPSS 63%

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack…

Fix: after 2.0.204
Fix from $2,300 2022-01-10
Debian Linux HIGH 7.5
CVE-2020-29050

SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can…

Fix: after 3.1.1
Fix from $1,950 2022-01-10
Debian Linux MEDIUM 5.9
CVE-2022-22707EPSS 9%

In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes repr…

Fix: after 1.4.63
Fix from $1,600 2022-01-06
Debian Linux MEDIUM 6.1
CVE-2021-46144

Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

Fix: 1.4.13 / 1.5.2+
Fix from $1,600 2022-01-06
Debian Linux MEDIUM 6.5
CVE-2021-28711

Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspec…

Patch available
Fix from $1,600 2022-01-05
Debian Linux MEDIUM 6.5
CVE-2021-28712

Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspec…

Patch available
Fix from $1,600 2022-01-05
Debian Linux MEDIUM 6.5
CVE-2021-28713

Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspec…

Patch available
Fix from $1,600 2022-01-05
Debian Linux HIGH 7.5
CVE-2021-41141

PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RT…

Fix: after 2.11.1
Fix from $1,950 2022-01-04
Debian Linux HIGH 7.5
CVE-2021-3842

nltk is vulnerable to Inefficient Regular Expression Complexity

Fix: 3.6.6+
Fix from $1,950 2022-01-04
Debian Linux HIGH 7.1
CVE-2021-45972

The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data t…

No fix yet
Fix from $1,950 2022-01-01
Debian Linux HIGH 8.8
CVE-2021-45960

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.…

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-01
Debian Linux MEDIUM 5.5
CVE-2021-45943

GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and …

Fix: after 3.4.0
Fix from $1,600 2022-01-01
Debian Linux MEDIUM 5.5
CVE-2021-45944

Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

Fix: after 9.53.3
Fix from $1,600 2022-01-01
Debian Linux MEDIUM 5.5
CVE-2021-45949

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

Fix: after 9.54.0
Fix from $1,600 2022-01-01
Debian Linux HIGH 7.8
CVE-2021-45909

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to writ…

No fix yet
Fix from $1,950 2021-12-28
Debian Linux HIGH 7.8
CVE-2021-45910

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside …

No fix yet
Fix from $1,950 2021-12-28
Debian Linux HIGH 7.8
CVE-2021-45911

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside t…

No fix yet
Fix from $1,950 2021-12-28