Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2021-43332 In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could… Debian Linux 2.1.36+ Fix from $1,6002021-11-12 MEDIUM 6.1 CVE-2021-43331 In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. Debian Linux 2.1.36+ Fix from $1,6002021-11-12 MEDIUM 6.5 CVE-2021-3911 If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. Debian Linux 1.3.0+ Fix from $1,6002021-11-11 MEDIUM 6.5 CVE-2021-3912 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat… Debian Linux 1.3.0+ Fix from $1,6002021-11-11 CRITICAL 9.8 CVE-2021-3907 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr… Debian Linux 1.3.0+ Fix from $2,3002021-11-11 HIGH 7.5 CVE-2021-3908 OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne… Debian Linux 1.3.0+ Fix from $1,9502021-11-11 HIGH 7.5 CVE-2021-3909 OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically… Debian Linux 1.3.0+ Fix from $1,9502021-11-11 HIGH 7.5 CVE-2021-3910 OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character). Debian Linux 1.4.0+ Fix from $1,9502021-11-11 HIGH 7.5 CVE-2021-43173 In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feedin… Debian Linux 0.10.2+ Fix from $1,9502021-11-09 HIGH 7.5 CVE-2021-43174 NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding ca… Debian Linux 0.10.2+ Fix from $1,9502021-11-09 HIGH 7.5 CVE-2021-43114 FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers … Debian Linux 1.5.2+ Fix from $1,9502021-11-09 CRITICAL 9.1 CVE-2021-43400 An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu… Debian Linux Patch available Fix from $2,3002021-11-04 MEDIUM 6.5 CVE-2021-22960 The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smug… Debian Linux 2.1.4 / 6.0.6+ Fix from $1,6002021-11-03 MEDIUM 5.5 CVE-2021-40985 A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. Debian Linux 1.9.12+ Fix from $1,6002021-11-03 MEDIUM 5.9 CVE-2021-38502 Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept trans… Debian Linux 91.2+ Fix from $1,6002021-11-03 MEDIUM 5.3 CVE-2021-25219EPSS 8% In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as we… Debian Linux 9.11.36 / 9.16.22+ Fix from $1,6002021-10-27 HIGH 8.0 CVE-2021-42097 GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain … Debian Linux 2.1.35+ Fix from $1,9502021-10-21 HIGH 7.8 CVE-2021-42771 Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversa… Debian Linux 2.9.1+ Fix from $1,9502021-10-20 HIGH 7.5 CVE-2021-37136EPSS 6% The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size u… Debian Linux 2.2.4 / 4.1.68+ Fix from $1,9502021-10-19 HIGH 7.5 CVE-2021-37137EPSS 7% The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved… Debian Linux 4.1.68 / 12.0.0.4.6+ Fix from $1,9502021-10-19 HIGH 7.5 CVE-2021-41990EPSS 7% The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can… Debian Linux 5.9.4+ Fix from $1,9502021-10-18 HIGH 7.5 CVE-2021-41991EPSS 5% The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to … Debian Linux 5.9.4+ Fix from $1,9502021-10-18 MEDIUM 6.1 CVE-2021-40732 XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memor… Debian Linux after 2020.1 Fix from $1,6002021-10-13 MEDIUM 5.3 CVE-2021-42326 Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter. Debian Linux 4.1.5 / 4.2.3+ Fix from $1,6002021-10-12 MEDIUM 6.5 CVE-2021-3671 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authen… Debian Linux 4.13.12 / 4.14.8+ Fix from $1,6002021-10-12 HIGH 7.5 CVE-2021-25634 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur… Debian Linux 7.0.6 / 7.1.2+ Fix from $1,9502021-10-12 HIGH 7.5 CVE-2021-42260 TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a cr… Debian Linux after 2.6.2 Fix from $1,9502021-10-11 HIGH 7.5 CVE-2021-25633 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur… Debian Linux 7.0.6 / 7.1.2+ Fix from $1,9502021-10-11 HIGH 7.8 CVE-2021-41133 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak … Debian Linux 1.8.2 / 1.10.4+ Fix from $1,9502021-10-08 MEDIUM 6.5 CVE-2021-41125 Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a… Debian Linux 1.8.1 / 2.5.1+ Fix from $1,6002021-10-06