Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.0
CVE-2021-3968

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3610+
Fix from $1,950 2021-11-19
Fedora HIGH 7.8
CVE-2021-3973

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3611+
Fix from $1,950 2021-11-19
Fedora HIGH 7.8
CVE-2021-3974

vim is vulnerable to Use After Free

Fix: 8.2.3612+
Fix from $1,950 2021-11-19
Fedora CRITICAL 9.8
CVE-2021-44026 KEVEPSS 43%

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

Fix: 1.3.17 / 1.4.12+
Fix from $2,300 2021-11-19
Fedora MEDIUM 6.1
CVE-2021-44025

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning me…

Fix: 1.3.17 / 1.4.12+
Fix from $1,600 2021-11-19
Fedora CRITICAL 9.8
CVE-2021-27023

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different ho…

Fix: 6.17.1 / 6.25.1+
Fix from $2,300 2021-11-18
Fedora MEDIUM 6.5
CVE-2021-27025

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior…

Fix: 6.25.1 / 7.12.1+
Fix from $1,600 2021-11-18
Fedora MEDIUM 5.0
CVE-2021-41190

The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specific…

Fix: after 1.0.1
Fix from $1,600 2021-11-17
Fedora MEDIUM 6.5
CVE-2021-43337

SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the…

Fix: 21.08.4+
Fix from $1,600 2021-11-17
Fedora HIGH 7.2
CVE-2021-42383

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate…

Mitigation only
Fix from $1,950 2021-11-15
Fedora HIGH 7.2
CVE-2021-42384

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_s…

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora HIGH 7.2
CVE-2021-42385

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate…

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora HIGH 7.2
CVE-2021-42386

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc …

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora CRITICAL 9.8
CVE-2021-42377

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell c…

Mitigation only
Fix from $2,300 2021-11-15
Fedora HIGH 7.2
CVE-2021-42378

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i…

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora HIGH 7.2
CVE-2021-42379

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_inp…

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora HIGH 7.2
CVE-2021-42380

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar f…

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora HIGH 7.2
CVE-2021-42381

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_ini…

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora HIGH 7.2
CVE-2021-42382

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s…

Fix: after 1.33.1
Fix from $1,950 2021-11-15
Fedora MEDIUM 5.5
CVE-2021-42373

A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given

Mitigation only
Fix from $1,600 2021-11-15
Fedora MEDIUM 5.5
CVE-2021-42375

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the she…

No fix yet
Fix from $1,600 2021-11-15
Fedora MEDIUM 5.5
CVE-2021-42376

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation aft…

Fix: 1.34.0+
Fix from $1,600 2021-11-15
Fedora MEDIUM 5.3
CVE-2021-42374

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompres…

Fix: after 1.33.1
Fix from $1,600 2021-11-15
Fedora CRITICAL 9.8
CVE-2021-43616

The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from pa…

Fix: after 8.1.3
Fix from $2,300 2021-11-13
Fedora MEDIUM 5.5
CVE-2020-23903

A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafte…

Patch available
Fix from $1,600 2021-11-10
Fedora MEDIUM 5.5
CVE-2021-43519

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

Fix: 5.3.5 / 5.4.4+
Fix from $1,600 2021-11-09
Fedora HIGH 8.8
CVE-2021-42072

An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify …

Fix: 2.4.0+
Fix from $1,950 2021-11-08
Fedora CRITICAL 9.8
CVE-2021-35368

OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pa…

Fix: 3.1.2 / 3.2.1+
Fix from $2,300 2021-11-05
Fedora HIGH 7.8
CVE-2021-3927

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3581+
Fix from $1,950 2021-11-05
Fedora HIGH 7.8
CVE-2021-3928

vim is vulnerable to Use of Uninitialized Variable

Fix: 8.2.3582+
Fix from $1,950 2021-11-05