Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.5
CVE-2021-43332

In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could…

Fix: 2.1.36+
Fix from $1,600 2021-11-12
Debian Linux MEDIUM 6.1
CVE-2021-43331

In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.

Fix: 2.1.36+
Fix from $1,600 2021-11-12
Debian Linux MEDIUM 6.5
CVE-2021-3911

If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.

Fix: 1.3.0+
Fix from $1,600 2021-11-11
Debian Linux MEDIUM 6.5
CVE-2021-3912

OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat…

Fix: 1.3.0+
Fix from $1,600 2021-11-11
Debian Linux CRITICAL 9.8
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…

Fix: 1.3.0+
Fix from $2,300 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3908

OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3909

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3910

OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).

Fix: 1.4.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-43173

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feedin…

Fix: 0.10.2+
Fix from $1,950 2021-11-09
Debian Linux HIGH 7.5
CVE-2021-43174

NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding ca…

Fix: 0.10.2+
Fix from $1,950 2021-11-09
Debian Linux HIGH 7.5
CVE-2021-43114

FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers …

Fix: 1.5.2+
Fix from $1,950 2021-11-09
Debian Linux CRITICAL 9.1
CVE-2021-43400

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…

Patch available
Fix from $2,300 2021-11-04
Debian Linux MEDIUM 6.5
CVE-2021-22960

The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smug…

Fix: 2.1.4 / 6.0.6+
Fix from $1,600 2021-11-03
Debian Linux MEDIUM 5.5
CVE-2021-40985

A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

Fix: 1.9.12+
Fix from $1,600 2021-11-03
Debian Linux MEDIUM 5.9
CVE-2021-38502

Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept trans…

Fix: 91.2+
Fix from $1,600 2021-11-03
Debian Linux MEDIUM 5.3
CVE-2021-25219EPSS 8%

In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as we…

Fix: 9.11.36 / 9.16.22+
Fix from $1,600 2021-10-27
Debian Linux HIGH 8.0
CVE-2021-42097

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain …

Fix: 2.1.35+
Fix from $1,950 2021-10-21
Debian Linux HIGH 7.8
CVE-2021-42771

Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversa…

Fix: 2.9.1+
Fix from $1,950 2021-10-20
Debian Linux HIGH 7.5
CVE-2021-37136EPSS 6%

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size u…

Fix: 2.2.4 / 4.1.68+
Fix from $1,950 2021-10-19
Debian Linux HIGH 7.5
CVE-2021-37137EPSS 7%

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved…

Fix: 4.1.68 / 12.0.0.4.6+
Fix from $1,950 2021-10-19
Debian Linux HIGH 7.5
CVE-2021-41990EPSS 7%

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can…

Fix: 5.9.4+
Fix from $1,950 2021-10-18
Debian Linux HIGH 7.5
CVE-2021-41991EPSS 5%

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to …

Fix: 5.9.4+
Fix from $1,950 2021-10-18
Debian Linux MEDIUM 6.1
CVE-2021-40732

XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memor…

Fix: after 2020.1
Fix from $1,600 2021-10-13
Debian Linux MEDIUM 5.3
CVE-2021-42326

Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

Fix: 4.1.5 / 4.2.3+
Fix from $1,600 2021-10-12
Debian Linux MEDIUM 6.5
CVE-2021-3671

A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authen…

Fix: 4.13.12 / 4.14.8+
Fix from $1,600 2021-10-12
Debian Linux HIGH 7.5
CVE-2021-25634

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2021-10-12
Debian Linux HIGH 7.5
CVE-2021-42260

TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a cr…

Fix: after 2.6.2
Fix from $1,950 2021-10-11
Debian Linux HIGH 7.5
CVE-2021-25633

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2021-10-11
Debian Linux HIGH 7.8
CVE-2021-41133

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak …

Fix: 1.8.2 / 1.10.4+
Fix from $1,950 2021-10-08
Debian Linux MEDIUM 6.5
CVE-2021-41125

Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a…

Fix: 1.8.1 / 2.5.1+
Fix from $1,600 2021-10-06