Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2021-20302
A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be process…
Debian Linux
2.5.4+
CRITICAL 9.8
CVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Debian Linux
No fix yet
HIGH 7.5
CVE-2022-21716
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is ab…
Debian Linux
22.2.0+
HIGH 7.5
CVE-2022-23648EPSS 27%
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.1…
Debian Linux
1.4.13 / 1.5.10+
MEDIUM 6.5
CVE-2022-0577
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
Debian Linux
2.6.1+
HIGH 7.8
CVE-2022-0545
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing…
Debian Linux
2.83.19 / 2.93.8+
MEDIUM 6.0
CVE-2021-3607
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handl…
Debian Linux
6.1.0+
MEDIUM 6.0
CVE-2021-3608
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA…
Debian Linux
6.1.0+
MEDIUM 5.5
CVE-2022-0544
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafte…
Debian Linux
2.83.19 / 2.93.8+
HIGH 8.8
CVE-2022-24407
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Debian Linux
after 2.1.27
MEDIUM 6.5
CVE-2022-24599
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak s…
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2022-23608
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…
Debian Linux
16.8.0 / 16.24.1+
HIGH 8.8
CVE-2021-44142EPSS 74%
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperabilit…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2016-1239
duck before 0.10 did not properly handle loading of untrusted code from the current directory.
Duck
0.10+
HIGH 8.8
CVE-2020-25722
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause…
Debian Linux
4.13.14 / 4.14.10+
HIGH 8.1
CVE-2020-25717
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…
Debian Linux
Patch available
HIGH 7.2
CVE-2020-25719
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b…
Debian Linux
Patch available
MEDIUM 5.9
CVE-2016-2124
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2022-25315
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
Debian Linux
2.4.5 / 3.1+
HIGH 7.5
CVE-2022-25314
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
Debian Linux
2.4.5 / 3.1+
MEDIUM 6.5
CVE-2022-25313
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
Debian Linux
2.4.5 / 3.1+
CRITICAL 9.8
CVE-2021-43299
Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copi…
Debian Linux
after 2.11.1
CRITICAL 9.8
CVE-2021-43300
Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is co…
Debian Linux
after 2.11.1
CRITICAL 9.8
CVE-2021-43301
Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is …
Debian Linux
after 2.11.1
CRITICAL 9.8
CVE-2021-43303
Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an o…
Debian Linux
after 2.11.1
CRITICAL 9.1
CVE-2021-43302
Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when t…
Debian Linux
after 2.11.1
HIGH 7.8
CVE-2021-3560 KEVEPSS 22%
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r…
Debian Linux
0.119+
CRITICAL 9.8
CVE-2022-25235
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a c…
Debian Linux
2.4.5 / 3.1+
CRITICAL 9.8
CVE-2022-25236EPSS 36%
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Debian Linux
2.4.5 / 3.1+
CRITICAL 9.8
CVE-2021-20001
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions…
Debian Linux
2.12.16+