Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2021-43845 PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data fi… Debian Linux after 2.11.1 Fix from $2,3002021-12-27 CRITICAL 9.8 CVE-2021-40393 An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a… Debian Linux No fix yet Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2021-40394 An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a… Debian Linux No fix yet Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2021-37706 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S… Debian Linux 16.8.0 / 16.24.1+ Fix from $2,3002021-12-22 HIGH 7.3 CVE-2021-43804 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S… Debian Linux after 2.11.1 Fix from $1,9502021-12-22 CRITICAL 9.8 CVE-2021-44732 Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. Debian Linux 2.16.12 / 2.28.0+ Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-23450EPSS 30% All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. Debian Linux 1.17.0+ Fix from $2,3002021-12-17 HIGH 7.5 CVE-2021-45098 An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP… Debian Linux 6.0.4+ Fix from $1,9502021-12-16 MEDIUM 6.1 CVE-2021-45085 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user vis… Debian Linux 40.4 / 41.1+ Fix from $1,6002021-12-16 MEDIUM 6.1 CVE-2021-45086 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF… Debian Linux 40.4 / 41.1+ Fix from $1,6002021-12-16 MEDIUM 6.1 CVE-2021-45087 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page … Debian Linux 40.4 / 41.1+ Fix from $1,6002021-12-16 MEDIUM 6.1 CVE-2021-45088 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. Debian Linux 40.4 / 41.1+ Fix from $1,6002021-12-16 CRITICAL 9.8 CVE-2021-43113EPSS 5% iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost… Debian Linux 7.1.17+ Fix from $2,3002021-12-15 CRITICAL 9.8 CVE-2021-44538 The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic… Debian Linux 1.6.0 / 1.9.7-sc1+ Fix from $2,3002021-12-14 MEDIUM 6.5 CVE-2021-43797 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients… Debian Linux 2.5.3 / 4.1.71+ Fix from $1,6002021-12-09 MEDIUM 6.5 CVE-2021-43528 Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive ch… Debian Linux 91.4.0+ Fix from $1,6002021-12-08 MEDIUM 5.0 CVE-2021-43784 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serializ… Debian Linux 1.0.3+ Fix from $1,6002021-12-06 HIGH 8.8 CVE-2021-44227 In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin passwo… Debian Linux 2.1.38+ Fix from $1,9502021-12-02 HIGH 8.8 CVE-2019-8922 A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destin… Debian Linux after 5.48 Fix from $1,9502021-11-29 MEDIUM 6.5 CVE-2019-8921 An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By c… Debian Linux after 5.48 Fix from $1,6002021-11-29 HIGH 8.8 CVE-2021-28707 PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond t… Debian Linux after 4.15.1 Fix from $1,9502021-11-24 HIGH 8.8 CVE-2021-28708 PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond t… Debian Linux after 4.15.1 Fix from $1,9502021-11-24 CRITICAL 9.8 CVE-2021-44143 A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted ma… Debian Linux after 1.4.3 Fix from $2,3002021-11-22 HIGH 8.8 CVE-2021-21898 A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-cra… Debian Linux No fix yet Fix from $1,9502021-11-19 CRITICAL 9.8 CVE-2021-40391 An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forke… Debian Linux No fix yet Fix from $2,3002021-11-19 HIGH 8.8 CVE-2021-21900 A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dx… Debian Linux No fix yet Fix from $1,9502021-11-19 MEDIUM 6.5 CVE-2021-22959 The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhtt… Debian Linux 2.1.4 / 6.0.6+ Fix from $1,6002021-11-15 HIGH 7.5 CVE-2021-43618 GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, … Debian Linux after 6.2.1 Fix from $1,9502021-11-15 CRITICAL 9.8 CVE-2021-3918 json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') Debian Linux 0.4.0+ Fix from $2,3002021-11-13 MEDIUM 6.5 CVE-2021-41229 BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will … Debian Linux No fix yet Fix from $1,6002021-11-12