Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.8
CVE-2021-31566

An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file ou…

Patch available
Fix from $1,950 2022-08-23
Fedora HIGH 7.5
CVE-2022-25761

The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on …

Fix: 1.2.5+
Fix from $1,950 2022-08-23
Fedora MEDIUM 5.5
CVE-2022-2923

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.

Fix: 9.0.0240+
Fix from $1,600 2022-08-22
Fedora HIGH 7.8
CVE-2022-2889

Use After Free in GitHub repository vim/vim prior to 9.0.0225.

Fix: 9.0.0225+
Fix from $1,950 2022-08-19
Fedora HIGH 7.8
CVE-2022-37047

The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this …

No fix yet
Fix from $1,950 2022-08-18
Fedora HIGH 7.8
CVE-2022-37048

The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: …

No fix yet
Fix from $1,950 2022-08-18
Fedora HIGH 7.8
CVE-2022-37049

The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is dif…

No fix yet
Fix from $1,950 2022-08-18
Fedora MEDIUM 5.5
CVE-2022-2867

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcro…

Fix: 4.4.0+
Fix from $1,600 2022-08-17
Fedora MEDIUM 5.5
CVE-2022-2868

libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is ab…

Fix: 4.4.0+
Fix from $1,600 2022-08-17
Fedora MEDIUM 5.5
CVE-2022-2869

libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker wh…

Fix: 4.4.0+
Fix from $1,600 2022-08-17
Fedora HIGH 7.8
CVE-2022-2862

Use After Free in GitHub repository vim/vim prior to 9.0.0221.

Fix: 9.0.0221+
Fix from $1,950 2022-08-17
Fedora HIGH 7.8
CVE-2022-2849

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.

Fix: 9.0.0220+
Fix from $1,950 2022-08-17
Fedora HIGH 7.8
CVE-2022-2845

Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.

Fix: 9.0.0218+
Fix from $1,950 2022-08-17
Fedora HIGH 7.8
CVE-2022-2817

Use After Free in GitHub repository vim/vim prior to 9.0.0213.

Fix: 9.0.0213+
Fix from $1,950 2022-08-15
Fedora HIGH 7.8
CVE-2022-2816

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.

Fix: 9.0.0212+
Fix from $1,950 2022-08-15
Fedora HIGH 7.8
CVE-2022-38223

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It …

No fix yet
Fix from $1,950 2022-08-15
Fedora HIGH 7.8
CVE-2022-2819

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.

Fix: 9.0.0211+
Fix from $1,950 2022-08-15
Fedora HIGH 7.5
CVE-2022-38150

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1…

Mitigation only
Fix from $1,950 2022-08-11
Fedora MEDIUM 5.5
CVE-2022-2719

In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image …

Fix: 7.1.0-30+
Fix from $1,600 2022-08-10
Fedora CRITICAL 9.1
CVE-2021-33643

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longl…

Fix: 1.2.21+
Fix from $2,300 2022-08-10
Fedora HIGH 8.1
CVE-2021-33644

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longn…

Fix: 1.2.21+
Fix from $1,950 2022-08-10
Fedora HIGH 7.5
CVE-2021-33645

The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.

Fix: 1.2.21+
Fix from $1,950 2022-08-10
Fedora HIGH 7.5
CVE-2021-33646

The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.

Fix: 1.2.21+
Fix from $1,950 2022-08-10
Fedora HIGH 7.5
CVE-2022-37451

Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.

Fix: 4.96+
Fix from $1,950 2022-08-06
Fedora CRITICAL 9.8
CVE-2022-37434EPSS 18%

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl…

Fix: after 1.2.12
Fix from $2,300 2022-08-05
Fedora HIGH 7.4
CVE-2022-29154

An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peer…

Fix: 3.2.5+
Fix from $1,950 2022-08-02
Fedora HIGH 7.5
CVE-2022-35922

Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memo…

Fix: 0.26.5+
Fix from $1,950 2022-08-01
Fedora MEDIUM 6.5
CVE-2022-30698

NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by t…

Fix: 1.16.2+
Fix from $1,600 2022-08-01
Fedora MEDIUM 6.5
CVE-2022-30699

NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by …

Fix: 1.16.2+
Fix from $1,600 2022-08-01
Fedora MEDIUM 6.5
CVE-2022-34526

A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service …

Patch available
Fix from $1,600 2022-07-29