Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2023-39948

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.…

Fix: 2.6.5+
Fix from $1,950 2023-08-11
Debian Linux HIGH 7.5
CVE-2023-39949

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5…

Fix: 2.6.5+
Fix from $1,950 2023-08-11
Debian Linux MEDIUM 6.7
CVE-2022-41804

Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable e…

Mitigation only
Fix from $1,600 2023-08-11
Debian Linux MEDIUM 5.5
CVE-2023-20588EPSS 11%

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

Mitigation only
Fix from $1,600 2023-08-08
Debian Linux MEDIUM 6.5
CVE-2023-36054

lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated u…

Fix: 1.20.2+
Fix from $1,600 2023-08-07
Debian Linux MEDIUM 6.3
CVE-2023-38745

Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via th…

Fix: 3.1.6+
Fix from $1,600 2023-07-25
Debian Linux MEDIUM 5.5
CVE-2023-20593EPSS 5%

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

Patch available
Fix from $1,600 2023-07-24
Debian Linux HIGH 7.5
CVE-2023-3417

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document fi…

Fix: 102.13.1 / 115.0.1+
Fix from $1,950 2023-07-24
Debian Linux MEDIUM 5.1
CVE-2023-22041

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Suppo…

Patch available
Fix from $1,600 2023-07-18
Debian Linux HIGH 7.5
CVE-2023-38403

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

Fix: 3.14 / 13.6.1+
Fix from $1,950 2023-07-17
Debian Linux HIGH 7.8
CVE-2023-21255

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,950 2023-07-13
Debian Linux MEDIUM 6.7
CVE-2023-21400

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of pr…

No fix yet
Fix from $1,600 2023-07-13
Debian Linux MEDIUM 6.5
CVE-2023-3618

A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in li…

Fix: 4.5.1+
Fix from $1,600 2023-07-12
Debian Linux MEDIUM 5.0
CVE-2023-35936

Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.1…

Fix: 3.1.4+
Fix from $1,600 2023-07-05
Debian Linux HIGH 7.8
CVE-2023-36664

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Fix: after 10.01.2
Fix from $1,950 2023-06-25
Debian Linux HIGH 7.5
CVE-2023-36661

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in…

Fix: 3.2.4+
Fix from $1,950 2023-06-25
Debian Linux HIGH 7.5
CVE-2023-2828

Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent…

Fix: after 9.19.13
Fix from $1,950 2023-06-21
Debian Linux HIGH 7.5
CVE-2023-2911

If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`…

Fix: after 9.18.15
Fix from $1,950 2023-06-21
Debian Linux MEDIUM 5.3
CVE-2023-34410

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always …

Fix: 5.15.15 / 6.2.9+
Fix from $1,600 2023-06-05
Debian Linux MEDIUM 5.5
CVE-2023-32324

OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker …

Fix: after 2.4.2
Fix from $1,600 2023-06-01
Debian Linux MEDIUM 5.3
CVE-2023-32762

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transp…

Fix: 5.15.14 / 6.2.9+
Fix from $1,600 2023-05-28
Debian Linux HIGH 7.5
CVE-2023-32307

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.…

Fix: 1.13.15+
Fix from $1,950 2023-05-26
Debian Linux HIGH 7.8
CVE-2023-0950

Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a sp…

Fix: 7.4.6 / 7.5.2+
Fix from $1,950 2023-05-25
Debian Linux MEDIUM 5.3
CVE-2023-2255

Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external…

Fix: 7.4.7 / 7.5.3+
Fix from $1,600 2023-05-25
Debian Linux HIGH 7.5
CVE-2023-31490

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

No fix yet
Fix from $1,950 2023-05-09
Debian Linux MEDIUM 6.5
CVE-2022-43681

An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option leng…

Fix: after 8.4
Fix from $1,600 2023-05-03
Debian Linux MEDIUM 6.5
CVE-2022-40302

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC …

Fix: after 8.4
Fix from $1,600 2023-05-03
Debian Linux MEDIUM 6.5
CVE-2022-40318

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC …

Fix: after 8.4
Fix from $1,600 2023-05-03
Debian Linux MEDIUM 6.5
CVE-2023-28484

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in x…

Fix: 2.10.4+
Fix from $1,600 2023-04-24
Debian Linux MEDIUM 6.5
CVE-2023-29469

An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can prod…

Fix: 2.10.4+
Fix from $1,600 2023-04-24