Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-24810 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can us… Debian Linux 5.9.2+ Fix from $1,9502024-04-16 HIGH 8.6 CVE-2024-32487 less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation… Debian Linux after 653 Fix from $1,9502024-04-13 MEDIUM 5.3 CVE-2024-28182EPSS 85% nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbound… Debian Linux 1.61.0+ Fix from $1,6002024-04-04 HIGH 7.8 CVE-2024-26739 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we'r… Debian Linux 5.10.238 / 5.15.182+ Fix from $1,9502024-04-03 HIGH 7.8 CVE-2023-52621 In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers These thre… Debian Linux 5.10.237 / 5.15.181+ Fix from $1,9502024-03-26 MEDIUM 5.3 CVE-2024-29025 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients… Debian Linux 4.1.108+ Fix from $1,6002024-03-25 HIGH 7.1 CVE-2024-30205 In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23. Debian Linux 9.6.23 / 29.3+ Fix from $1,9502024-03-25 MEDIUM 5.5 CVE-2024-30203 In Emacs before 29.3, Gnus treats inline MIME contents as trusted. Debian Linux 9.6.23 / 29.3+ Fix from $1,6002024-03-25 MEDIUM 6.8 CVE-2024-28102 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service att… Debian Linux 1.5.6+ Fix from $1,6002024-03-21 HIGH 7.5 CVE-2023-52159 A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd da… Debian Linux 1.0.4+ Fix from $1,9502024-03-18 HIGH 7.5 CVE-2024-1936 The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local ca… Debian Linux 115.8.1+ Fix from $1,9502024-03-04 HIGH 7.8 CVE-2023-52572 In the Linux kernel, the following vulnerability has been resolved: cifs: Fix UAF in cifs_demultiplex_thread() There is a UAF when xfstests on cifs… Debian Linux 5.4.297 / 5.10.237+ Fix from $1,9502024-03-02 HIGH 7.5 CVE-2024-27354 An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate c… Debian Linux 1.0.23 / 2.0.47+ Fix from $1,9502024-03-01 HIGH 7.5 CVE-2024-27355 An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a ce… Debian Linux 1.0.23 / 2.0.47+ Fix from $1,9502024-03-01 MEDIUM 6.5 CVE-2024-25082 Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. Debian Linux after 20230101 Fix from $1,6002024-02-26 HIGH 7.5 CVE-2024-22201 Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.… Debian Linux 9.4.54 / 10.0.20+ Fix from $1,9502024-02-26 MEDIUM 6.5 CVE-2023-52160 The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to… Debian Linux after 2.10 Fix from $1,6002024-02-22 HIGH 7.8 CVE-2024-26581 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on … Debian Linux 5.4.269 / 5.10.210+ Fix from $1,9502024-02-20 HIGH 7.5 CVE-2024-24814 mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Re… Debian Linux after 2.4.15.1 Fix from $1,9502024-02-13 MEDIUM 5.5 CVE-2024-1151 A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursive… Debian Linux after 6.7.8 Fix from $1,6002024-02-11 CRITICAL 9.8 CVE-2024-25714 In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the compa… Debian Linux after 1.1.3 Fix from $2,3002024-02-11 CRITICAL 9.8 CVE-2024-25189 libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side cha… Debian Linux No fix yet Fix from $2,3002024-02-08 MEDIUM 6.8 CVE-2024-24857 A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity … Debian Linux 6.7.12+ Fix from $1,6002024-02-05 MEDIUM 5.3 CVE-2024-24858 A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection o… Debian Linux after 6.7.12 Fix from $1,6002024-02-05 CRITICAL 9.8 CVE-2024-0808 Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious f… Debian Linux 121.0.6167.85+ Fix from $2,3002024-01-24 MEDIUM 5.9 CVE-2024-20926 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup… Debian Linux Patch available Fix from $1,6002024-01-16 HIGH 7.4 CVE-2024-20918 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo… Debian Linux Patch available Fix from $1,9502024-01-16 MEDIUM 5.3 CVE-2024-22049 httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted… Debian Linux 0.21.0+ Fix from $1,6002024-01-04 HIGH 7.0 CVE-2023-6270 A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct n… Debian Linux 6.9+ Fix from $1,9502024-01-04 HIGH 7.8 CVE-2023-7101 KEVEPSS 17% Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut… Debian Linux after 0.65 Fix from $1,9502023-12-24