Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2022-0534 A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malici… Debian Linux Patch available Fix from $1,6002022-02-09 HIGH 7.5 CVE-2022-21712 twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following… Debian Linux 22.1.0+ Fix from $1,9502022-02-07 CRITICAL 9.8 CVE-2021-38172 perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.) Perm Patch available Fix from $2,3002022-02-05 MEDIUM 5.5 CVE-2021-4043 NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0. Debian Linux 1.1.0+ Fix from $1,6002022-02-04 MEDIUM 5.3 CVE-2021-46671 options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client. Debian Linux 0.7.5+ Fix from $1,6002022-02-04 CRITICAL 9.8 CVE-2022-24300 Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injectio… Debian Linux 5.4.0+ Fix from $2,3002022-02-02 MEDIUM 6.5 CVE-2022-24301 In Minetest before 5.4.0, players can add or subtract items from a different player's inventory. Debian Linux 5.4.0+ Fix from $1,6002022-02-02 MEDIUM 6.5 CVE-2022-23607 treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq… Debian Linux 22.1.0+ Fix from $1,6002022-02-01 CRITICAL 9.1 CVE-2021-45079 In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the ca… Debian Linux 5.9.5+ Fix from $2,3002022-01-31 MEDIUM 5.5 CVE-2022-24130 xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted te… Debian Linux after 370 Fix from $1,6002022-01-31 HIGH 7.8 CVE-2022-0392 Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. Debian Linux 8.2.4218 / 12.6+ Fix from $1,9502022-01-28 CRITICAL 9.1 CVE-2022-23096 An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient He… Debian Linux after 1.40 Fix from $2,3002022-01-28 CRITICAL 9.1 CVE-2022-23097 An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read. Debian Linux after 1.40 Fix from $2,3002022-01-28 HIGH 7.5 CVE-2022-23098 An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received. Debian Linux after 1.40 Fix from $1,9502022-01-28 CRITICAL 9.1 CVE-2022-21722 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S… Debian Linux after 2.11.1 Fix from $2,3002022-01-27 CRITICAL 9.1 CVE-2022-21723 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S… Debian Linux 16.24.1 / 18.10.1+ Fix from $2,3002022-01-27 HIGH 7.5 CVE-2022-23990 Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. Debian Linux 2.4.4 / 3.1+ Fix from $1,9502022-01-26 HIGH 7.8 CVE-2022-0368 Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Debian Linux 8.2.4217 / 12.6+ Fix from $1,9502022-01-26 MEDIUM 5.5 CVE-2021-22570 Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file… Debian Linux 3.15.0+ Fix from $1,6002022-01-26 HIGH 7.8 CVE-2022-0361 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Debian Linux 8.2.4215 / 12.6+ Fix from $1,9502022-01-26 HIGH 7.8 CVE-2022-0359 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Debian Linux 8.2.4214 / 12.6+ Fix from $1,9502022-01-26 HIGH 7.8 CVE-2022-0351 Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2. Debian Linux 8.2 / 12.6+ Fix from $1,9502022-01-25 CRITICAL 9.1 CVE-2021-3850 Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21. Debian Linux after 5.20.21 Fix from $2,3002022-01-25 HIGH 7.8 CVE-2021-45845 The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted … Debian Linux Patch available Fix from $1,9502022-01-25 HIGH 7.8 CVE-2021-45844 Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. Debian Linux Patch available Fix from $1,9502022-01-25 CRITICAL 9.8 CVE-2022-23852 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. Debian Linux 2.4.4 / 3.1+ Fix from $2,3002022-01-24 HIGH 7.5 CVE-2022-23837EPSS 5% In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system,… Debian Linux 5.2.10 / 6.4.0+ Fix from $1,9502022-01-21 CRITICAL 9.8 CVE-2021-23518 The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create… Debian Linux 1.1.0+ Fix from $2,3002022-01-21 MEDIUM 5.5 CVE-2022-0319 Out-of-bounds Read in vim/vim prior to 8.2. Debian Linux 8.2.4154 / 13.0+ Fix from $1,6002022-01-21 CRITICAL 9.8 CVE-2022-0318 Heap-based Buffer Overflow in vim/vim prior to 8.2. Debian Linux 8.2.4151 / 13.0+ Fix from $2,3002022-01-21