Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-26049 Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookie… Debian Linux 9.4.51 / 10.0.14+ Fix from $1,6002023-04-18 MEDIUM 5.9 CVE-2023-21967 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affe… Debian Linux 8+ Fix from $1,6002023-04-18 MEDIUM 5.9 CVE-2023-21954 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are a… Debian Linux 8+ Fix from $1,6002023-04-18 MEDIUM 5.3 CVE-2023-21939 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are aff… Debian Linux 8+ Fix from $1,6002023-04-18 HIGH 7.4 CVE-2023-21930 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affe… Debian Linux 8+ Fix from $1,9502023-04-18 HIGH 8.2 CVE-2023-1668 A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying … Debian Linux 2.13.11 / 2.14.9+ Fix from $1,9502023-04-10 MEDIUM 6.5 CVE-2023-29415 An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does n… Debian Linux 1.3.0+ Fix from $1,6002023-04-06 CRITICAL 9.8 CVE-2023-28879EPSS 6% In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in… Debian Linux 10.01.0+ Fix from $2,3002023-03-31 CRITICAL 9.8 CVE-2022-23121EPSS 9% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… Debian Linux 3.1.13+ Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2022-23122 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… Debian Linux 3.1.13+ Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2022-23123 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to… Debian Linux 3.1.13+ Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2022-23124 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to… Debian Linux 3.1.13+ Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2022-23125 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… Debian Linux 3.1.13+ Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2022-0194 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… Debian Linux 3.1.13+ Fix from $2,3002023-03-28 HIGH 7.8 CVE-2023-0386 KEVEPSS 8% A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s… Debian Linux 5.15.91 / 6.1.9+ Fix from $1,9502023-03-22 HIGH 8.6 CVE-2022-42333 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c… Debian Linux after 4.17.0 Fix from $1,9502023-03-21 MEDIUM 6.5 CVE-2022-42334 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c… Debian Linux after 4.17.0 Fix from $1,6002023-03-21 HIGH 7.8 CVE-2022-42332 x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP)… Debian Linux Mitigation only Fix from $1,9502023-03-21 MEDIUM 6.0 CVE-2023-0330 A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like st… Debian Linux 7.2.3+ Fix from $1,6002023-03-06 HIGH 7.8 CVE-2023-27635 debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is… Debmany Mitigation only Fix from $1,9502023-03-05 HIGH 7.8 CVE-2023-26604 systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "sys… Debian Linux 246.7+ Fix from $1,9502023-03-03 HIGH 7.8 CVE-2023-25221 Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc. Debian Linux Patch available Fix from $1,9502023-03-01 MEDIUM 6.5 CVE-2023-24751 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to … Debian Linux Patch available Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2023-24752 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulne… Debian Linux Patch available Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2023-24754 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vuln… Debian Linux Patch available Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2023-24755 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulner… Debian Linux Patch available Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2023-24756 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulner… Debian Linux Patch available Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2023-24757 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vul… Debian Linux Patch available Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2023-24758 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vuln… Debian Linux Patch available Fix from $1,6002023-03-01 CRITICAL 9.8 CVE-2023-27372EPSS 100% SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… Debian Linux 3.2.18 / 4.0.10+ Fix from $2,3002023-02-28