Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2022-29153EPSS 9%

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows re…

Fix: 1.9.17 / 1.10.10+
Fix from $1,950 2022-04-19
Fedora MEDIUM 5.3
CVE-2021-42778

A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.

Fix: 0.22.0+
Fix from $1,600 2022-04-18
Fedora MEDIUM 5.3
CVE-2021-42779

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

Fix: 0.22.0+
Fix from $1,600 2022-04-18
Fedora MEDIUM 5.3
CVE-2021-42780

A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.

Fix: 0.22.0+
Fix from $1,600 2022-04-18
Fedora MEDIUM 5.3
CVE-2021-42781

Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.

Fix: 0.22.0+
Fix from $1,600 2022-04-18
Fedora MEDIUM 5.3
CVE-2021-42782

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

Fix: 0.22.0+
Fix from $1,600 2022-04-18
Fedora HIGH 7.8
CVE-2022-1381

global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass …

Fix: 8.2.4763 / 13.0+
Fix from $1,950 2022-04-18
Fedora MEDIUM 6.1
CVE-2022-1231

XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedde…

Fix: 1.2022.4+
Fix from $1,600 2022-04-15
Fedora HIGH 8.8
CVE-2022-28042

stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

Patch available
Fix from $1,950 2022-04-15
Fedora HIGH 8.8
CVE-2022-28048

STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.

Patch available
Fix from $1,950 2022-04-15
Fedora MEDIUM 6.5
CVE-2022-28041

stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers…

Patch available
Fix from $1,600 2022-04-15
Fedora HIGH 8.8
CVE-2022-24828

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a cod…

Fix: 1.10.26 / 2.2.12+
Fix from $1,950 2022-04-13
Fedora CRITICAL 9.1
CVE-2022-28805

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer o…

Fix: 5.4.5+
Fix from $2,300 2022-04-08
Fedora HIGH 7.8
CVE-2021-43138

In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObj…

Fix: 2.6.4 / 3.2.2+
Fix from $1,950 2022-04-06
Fedora HIGH 7.5
CVE-2022-27650

A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engi…

Fix: 1.4.4+
Fix from $1,950 2022-04-04
Fedora MEDIUM 6.8
CVE-2022-27651

A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) whe…

Fix: 1.25.0+
Fix from $1,600 2022-04-04
Fedora HIGH 7.5
CVE-2022-24785EPSS 6%

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (serve…

Fix: 2.29.2 / 5.21.0+
Fix from $1,950 2022-04-04
Fedora MEDIUM 5.5
CVE-2022-24191

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer …

Fix: 1.9.15+
Fix from $1,600 2022-04-04
Fedora HIGH 7.8
CVE-2022-1160

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

Fix: 8.2.4647+
Fix from $1,950 2022-03-30
Fedora HIGH 7.8
CVE-2022-1154

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

Fix: 8.2.4646+
Fix from $1,950 2022-03-30
Fedora MEDIUM 6.1
CVE-2022-28202

An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes …

Fix: 1.35.6 / 1.36.4+
Fix from $1,600 2022-03-30
Fedora MEDIUM 5.5
CVE-2022-1122

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fai…

Mitigation only
Fix from $1,600 2022-03-29
Fedora MEDIUM 6.5
CVE-2022-26280

Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.

No fix yet
Fix from $1,600 2022-03-28
Fedora HIGH 7.8
CVE-2022-27940

tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.

No fix yet
Fix from $1,950 2022-03-26
Fedora HIGH 7.8
CVE-2022-27941

tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.

No fix yet
Fix from $1,950 2022-03-26
Fedora HIGH 7.8
CVE-2022-27942

tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.

No fix yet
Fix from $1,950 2022-03-26
Fedora MEDIUM 5.5
CVE-2022-27939

tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.

No fix yet
Fix from $1,600 2022-03-26
Fedora MEDIUM 5.5
CVE-2022-27943

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

No fix yet
Fix from $1,600 2022-03-26
Fedora CRITICAL 9.8
CVE-2022-22995

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combin…

Fix: 5.19.117+
Fix from $2,300 2022-03-25
Fedora MEDIUM 6.1
CVE-2022-27920

libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.

Patch available
Fix from $1,600 2022-03-25