Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.1
CVE-2021-43845

PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data fi…

Fix: after 2.11.1
Fix from $2,300 2021-12-27
Debian Linux CRITICAL 9.8
CVE-2021-40393

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…

No fix yet
Fix from $2,300 2021-12-22
Debian Linux CRITICAL 9.8
CVE-2021-40394

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…

No fix yet
Fix from $2,300 2021-12-22
Debian Linux CRITICAL 9.8
CVE-2021-37706

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.8.0 / 16.24.1+
Fix from $2,300 2021-12-22
Debian Linux HIGH 7.3
CVE-2021-43804

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.11.1
Fix from $1,950 2021-12-22
Debian Linux CRITICAL 9.8
CVE-2021-44732

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

Fix: 2.16.12 / 2.28.0+
Fix from $2,300 2021-12-20
Debian Linux CRITICAL 9.8
CVE-2021-23450EPSS 30%

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

Fix: 1.17.0+
Fix from $2,300 2021-12-17
Debian Linux HIGH 7.5
CVE-2021-45098

An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP…

Fix: 6.0.4+
Fix from $1,950 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-45085

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user vis…

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-45086

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF…

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-45087

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page …

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-45088

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux CRITICAL 9.8
CVE-2021-43113EPSS 5%

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost…

Fix: 7.1.17+
Fix from $2,300 2021-12-15
Debian Linux CRITICAL 9.8
CVE-2021-44538

The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic…

Fix: 1.6.0 / 1.9.7-sc1+
Fix from $2,300 2021-12-14
Debian Linux MEDIUM 6.5
CVE-2021-43797

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients…

Fix: 2.5.3 / 4.1.71+
Fix from $1,600 2021-12-09
Debian Linux MEDIUM 6.5
CVE-2021-43528

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive ch…

Fix: 91.4.0+
Fix from $1,600 2021-12-08
Debian Linux MEDIUM 5.0
CVE-2021-43784

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serializ…

Fix: 1.0.3+
Fix from $1,600 2021-12-06
Debian Linux HIGH 8.8
CVE-2021-44227

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin passwo…

Fix: 2.1.38+
Fix from $1,950 2021-12-02
Debian Linux HIGH 8.8
CVE-2019-8922

A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destin…

Fix: after 5.48
Fix from $1,950 2021-11-29
Debian Linux MEDIUM 6.5
CVE-2019-8921

An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By c…

Fix: after 5.48
Fix from $1,600 2021-11-29
Debian Linux HIGH 8.8
CVE-2021-28707

PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond t…

Fix: after 4.15.1
Fix from $1,950 2021-11-24
Debian Linux HIGH 8.8
CVE-2021-28708

PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond t…

Fix: after 4.15.1
Fix from $1,950 2021-11-24
Debian Linux CRITICAL 9.8
CVE-2021-44143

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted ma…

Fix: after 1.4.3
Fix from $2,300 2021-11-22
Debian Linux HIGH 8.8
CVE-2021-21898

A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-cra…

No fix yet
Fix from $1,950 2021-11-19
Debian Linux CRITICAL 9.8
CVE-2021-40391

An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forke…

No fix yet
Fix from $2,300 2021-11-19
Debian Linux HIGH 8.8
CVE-2021-21900

A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dx…

No fix yet
Fix from $1,950 2021-11-19
Debian Linux MEDIUM 6.5
CVE-2021-22959

The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhtt…

Fix: 2.1.4 / 6.0.6+
Fix from $1,600 2021-11-15
Debian Linux HIGH 7.5
CVE-2021-43618

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, …

Fix: after 6.2.1
Fix from $1,950 2021-11-15
Debian Linux CRITICAL 9.8
CVE-2021-3918

json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Fix: 0.4.0+
Fix from $2,300 2021-11-13
Debian Linux MEDIUM 6.5
CVE-2021-41229

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will …

No fix yet
Fix from $1,600 2021-11-12