Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.8
CVE-2022-3324

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

Fix: 9.0.0598+
Fix from $1,950 2022-09-27
Fedora HIGH 7.5
CVE-2022-3204

A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegatio…

Fix: after 1.16.2
Fix from $1,950 2022-09-26
Fedora HIGH 7.8
CVE-2022-3297

Use After Free in GitHub repository vim/vim prior to 9.0.0579.

Fix: 9.0.0579+
Fix from $1,950 2022-09-25
Fedora HIGH 7.8
CVE-2022-3296

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

Fix: 9.0.0577+
Fix from $1,950 2022-09-25
Fedora MEDIUM 5.5
CVE-2022-3278

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.

Fix: 9.0.0552+
Fix from $1,600 2022-09-23
Fedora CRITICAL 9.8
CVE-2022-36944EPSS 9%

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction …

Fix: 2.9.0 / 2.13.9+
Fix from $2,300 2022-09-23
Fedora HIGH 7.5
CVE-2022-40188

Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack…

Fix: 5.5.3+
Fix from $1,950 2022-09-23
Fedora HIGH 7.8
CVE-2022-41322

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must displ…

Fix: 0.26.2+
Fix from $1,950 2022-09-23
Fedora HIGH 7.5
CVE-2022-1941

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.2…

Fix: 3.18.3 / 3.19.5+
Fix from $1,950 2022-09-22
Fedora HIGH 7.8
CVE-2022-3256

Use After Free in GitHub repository vim/vim prior to 9.0.0530.

Fix: 9.0.0530+
Fix from $1,950 2022-09-22
Fedora HIGH 7.5
CVE-2022-3080

By sending specific queries to the resolver, an attacker can cause named to crash.

Fix: 9.16.33 / 9.18.7+
Fix from $1,950 2022-09-21
Fedora CRITICAL 9.8
CVE-2022-39955

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field t…

Fix: 3.2.2 / 3.3.3+
Fix from $2,300 2022-09-20
Fedora CRITICAL 9.8
CVE-2022-39956

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a ch…

Fix: 3.2.2 / 3.3.3+
Fix from $2,300 2022-09-20
Fedora HIGH 7.5
CVE-2022-39957

The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optiona…

Fix: 3.2.2 / 3.3.3+
Fix from $1,950 2022-09-20
Fedora HIGH 7.5
CVE-2022-39958

The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by…

Fix: 3.2.2 / 3.3.3+
Fix from $1,950 2022-09-20
Fedora MEDIUM 5.5
CVE-2022-3213

A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a …

Fix: 6.9.12-62 / 7.1.0-47+
Fix from $1,600 2022-09-19
Fedora HIGH 7.8
CVE-2022-3235

Use After Free in GitHub repository vim/vim prior to 9.0.0490.

Fix: 9.0.0490+
Fix from $1,950 2022-09-18
Fedora HIGH 7.8
CVE-2022-3234

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.

Fix: 9.0.0483+
Fix from $1,950 2022-09-17
Fedora MEDIUM 5.5
CVE-2022-30674

Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure…

Fix: after 17.3
Fix from $1,600 2022-09-16
Fedora HIGH 7.8
CVE-2022-40673

KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.

Fix: 3.1.0+
Fix from $1,950 2022-09-14
Fedora MEDIUM 6.1
CVE-2022-40626

An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in ord…

Fix: after 6.0.6
Fix from $1,600 2022-09-14
Fedora HIGH 7.5
CVE-2022-38013

.NET Core and Visual Studio Denial of Service Vulnerability

Patch available
Fix from $1,950 2022-09-13
Fedora HIGH 8.8
CVE-2022-40320

cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.

Patch available
Fix from $1,950 2022-09-09
Fedora MEDIUM 6.5
CVE-2022-36087

OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malic…

Fix: 3.2.1+
Fix from $1,600 2022-09-09
Fedora MEDIUM 6.3
CVE-2022-36109

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary gro…

Fix: 20.10.18+
Fix from $1,600 2022-09-09
Fedora MEDIUM 6.1
CVE-2022-3123

Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.

Fix: 2022-07-31a+
Fix from $1,600 2022-09-05
Fedora HIGH 7.8
CVE-2022-39831

An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which …

Patch available
Fix from $1,950 2022-09-05
Fedora HIGH 7.8
CVE-2022-39832

An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows a…

No fix yet
Fix from $1,950 2022-09-05
Fedora HIGH 7.8
CVE-2022-3099

Use After Free in GitHub repository vim/vim prior to 9.0.0360.

Fix: 9.0.0360+
Fix from $1,950 2022-09-03
Fedora HIGH 8.8
CVE-2022-39170

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

Patch available
Fix from $1,950 2022-09-02