Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2022-37032 An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capabi… Debian Linux 8.4+ Fix from $2,3002022-09-19 HIGH 7.5 CVE-2022-28203 A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requestin… Debian Linux 1.35.6 / 1.36.4+ Fix from $1,9502022-09-19 HIGH 7.5 CVE-2022-40149 Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl… Debian Linux after 1.4.0 Fix from $1,9502022-09-16 HIGH 7.5 CVE-2022-40150 Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl… Debian Linux after 1.4.0 Fix from $1,9502022-09-16 MEDIUM 5.5 CVE-2022-38850 The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c. Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38851 Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This aff… Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38855 Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects m… Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38858 Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer… Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38860 Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder.… Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38861 The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c. Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38863 Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and … Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38864 Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencod… Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38865 Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects … Debian Linux No fix yet Fix from $1,6002022-09-15 MEDIUM 5.5 CVE-2022-38866 Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38… Debian Linux Mitigation only Fix from $1,6002022-09-15 MEDIUM 5.4 CVE-2018-25047 In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that coul… Debian Linux 3.1.47 / 4.2.1+ Fix from $1,6002022-09-15 HIGH 8.1 CVE-2022-40674 libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. Debian Linux 2.4.9+ Fix from $1,9502022-09-14 HIGH 7.5 CVE-2022-37797 In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It lead… Debian Linux No fix yet Fix from $1,9502022-09-12 MEDIUM 6.5 CVE-2022-38266 An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a craft… Debian Linux 1.80.0+ Fix from $1,6002022-09-09 HIGH 7.5 CVE-2022-40023 Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin… Debian Linux 1.2.2+ Fix from $1,9502022-09-07 HIGH 7.8 CVE-2022-3134 Use After Free in GitHub repository vim/vim prior to 9.0.0389. Debian Linux 9.0.0389+ Fix from $1,9502022-09-06 HIGH 7.8 CVE-2022-2735 A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between… Debian Linux after 0.11.3 Fix from $1,9502022-09-06 MEDIUM 6.5 CVE-2022-38749 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, … Debian Linux 1.31+ Fix from $1,6002022-09-05 MEDIUM 6.5 CVE-2022-38751 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, … Debian Linux 1.31+ Fix from $1,6002022-09-05 MEDIUM 5.5 CVE-2022-38750 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, … Debian Linux 1.31+ Fix from $1,6002022-09-05 HIGH 8.8 CVE-2022-3008 The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T… Debian Linux 2.6.0+ Fix from $1,9502022-09-05 HIGH 7.5 CVE-2020-29260 libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). Debian Linux Patch available Fix from $1,9502022-09-02 CRITICAL 9.8 CVE-2020-22669 Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters an… Debian Linux Patch available Fix from $2,3002022-09-02 MEDIUM 5.5 CVE-2020-35530 In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggere… Debian Linux Patch available Fix from $1,6002022-09-01 MEDIUM 5.5 CVE-2020-35531 In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data… Debian Linux Patch available Fix from $1,6002022-09-01 MEDIUM 5.5 CVE-2020-35532 In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be t… Debian Linux Patch available Fix from $1,6002022-09-01