Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-39948 eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.… Debian Linux 2.6.5+ Fix from $1,9502023-08-11 HIGH 7.5 CVE-2023-39949 eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5… Debian Linux 2.6.5+ Fix from $1,9502023-08-11 MEDIUM 6.7 CVE-2022-41804 Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable e… Debian Linux Mitigation only Fix from $1,6002023-08-11 MEDIUM 5.5 CVE-2023-20588EPSS 11% A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.  Debian Linux Mitigation only Fix from $1,6002023-08-08 MEDIUM 6.5 CVE-2023-36054 lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated u… Debian Linux 1.20.2+ Fix from $1,6002023-08-07 MEDIUM 6.3 CVE-2023-38745 Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via th… Debian Linux 3.1.6+ Fix from $1,6002023-07-25 MEDIUM 5.5 CVE-2023-20593EPSS 5% An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. Debian Linux Patch available Fix from $1,6002023-07-24 HIGH 7.5 CVE-2023-3417 Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document fi… Debian Linux 102.13.1 / 115.0.1+ Fix from $1,9502023-07-24 MEDIUM 5.1 CVE-2023-22041 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Suppo… Debian Linux Patch available Fix from $1,6002023-07-18 HIGH 7.5 CVE-2023-38403 iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. Debian Linux 3.14 / 13.6.1+ Fix from $1,9502023-07-17 HIGH 7.8 CVE-2023-21255 In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege wi… Debian Linux Patch available Fix from $1,9502023-07-13 MEDIUM 6.7 CVE-2023-21400 In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of pr… Debian Linux No fix yet Fix from $1,6002023-07-13 MEDIUM 6.5 CVE-2023-3618 A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in li… Debian Linux 4.5.1+ Fix from $1,6002023-07-12 MEDIUM 5.0 CVE-2023-35936 Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.1… Debian Linux 3.1.4+ Fix from $1,6002023-07-05 HIGH 7.8 CVE-2023-36664 Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). Debian Linux after 10.01.2 Fix from $1,9502023-06-25 HIGH 7.5 CVE-2023-36661 Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in… Debian Linux 3.2.4+ Fix from $1,9502023-06-25 HIGH 7.5 CVE-2023-2828 Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent… Debian Linux after 9.19.13 Fix from $1,9502023-06-21 HIGH 7.5 CVE-2023-2911 If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`… Debian Linux after 9.18.15 Fix from $1,9502023-06-21 MEDIUM 5.3 CVE-2023-34410 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always … Debian Linux 5.15.15 / 6.2.9+ Fix from $1,6002023-06-05 MEDIUM 5.5 CVE-2023-32324 OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker … Debian Linux after 2.4.2 Fix from $1,6002023-06-01 MEDIUM 5.3 CVE-2023-32762 An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transp… Debian Linux 5.15.14 / 6.2.9+ Fix from $1,6002023-05-28 HIGH 7.5 CVE-2023-32307 Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.… Debian Linux 1.13.15+ Fix from $1,9502023-05-26 HIGH 7.8 CVE-2023-0950 Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a sp… Debian Linux 7.4.6 / 7.5.2+ Fix from $1,9502023-05-25 MEDIUM 5.3 CVE-2023-2255 Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external… Debian Linux 7.4.7 / 7.5.3+ Fix from $1,6002023-05-25 HIGH 7.5 CVE-2023-31490 An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function. Debian Linux No fix yet Fix from $1,9502023-05-09 MEDIUM 6.5 CVE-2022-43681 An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option leng… Debian Linux after 8.4 Fix from $1,6002023-05-03 MEDIUM 6.5 CVE-2022-40302 An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC … Debian Linux after 8.4 Fix from $1,6002023-05-03 MEDIUM 6.5 CVE-2022-40318 An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC … Debian Linux after 8.4 Fix from $1,6002023-05-03 MEDIUM 6.5 CVE-2023-28484 In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in x… Debian Linux 2.10.4+ Fix from $1,6002023-04-24 MEDIUM 6.5 CVE-2023-29469 An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can prod… Debian Linux 2.10.4+ Fix from $1,6002023-04-24