Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.5
CVE-2021-29463

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Fix: 0.27.4+
Fix from $1,600 2021-04-30
Fedora MEDIUM 6.5
CVE-2020-15225

django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically gener…

Fix: 2.4.0+
Fix from $1,600 2021-04-29
Fedora HIGH 7.8
CVE-2021-3472

A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalat…

Fix: 1.20.11+
Fix from $1,950 2021-04-26
Fedora MEDIUM 6.5
CVE-2021-29470

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Fix: after 0.27.3
Fix from $1,600 2021-04-23
Fedora HIGH 7.8
CVE-2021-31607

In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on…

Fix: after 3002.6
Fix from $1,950 2021-04-23
Fedora HIGH 7.4
CVE-2021-0232

An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific informatio…

Fix: 2.35.6 / 2.36.2+
Fix from $1,950 2021-04-22
Fedora MEDIUM 5.5
CVE-2021-29458

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was …

Fix: 0.27.4+
Fix from $1,600 2021-04-19
Fedora HIGH 7.8
CVE-2021-29457

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was…

Fix: 0.27.4+
Fix from $1,950 2021-04-19
Fedora HIGH 7.5
CVE-2021-28484

An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler …

Fix: 3.0.1+
Fix from $1,950 2021-04-14
Fedora MEDIUM 5.5
CVE-2021-29338

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacke…

Patch available
Fix from $1,600 2021-04-14
Fedora MEDIUM 5.5
CVE-2021-27815

NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to caus…

Fix: after 0.6.22
Fix from $1,600 2021-04-14
Fedora MEDIUM 6.5
CVE-2021-21393

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.28.0+
Fix from $1,600 2021-04-12
Fedora MEDIUM 6.3
CVE-2021-21392

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.28.0+
Fix from $1,600 2021-04-12
Fedora MEDIUM 6.5
CVE-2021-21394

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.28.0+
Fix from $1,600 2021-04-12
Fedora HIGH 7.8
CVE-2021-30184

GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the…

Patch available
Fix from $1,950 2021-04-07
Fedora HIGH 7.5
CVE-2021-29424

The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which …

Fix: 2.0000+
Fix from $1,950 2021-04-06
Fedora CRITICAL 9.8
CVE-2021-20307

Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory val…

Fix: after 2.9.19
Fix from $2,300 2021-04-05
Fedora HIGH 8.1
CVE-2021-20305

A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the El…

Fix: 3.7.2+
Fix from $1,950 2021-04-05
Fedora CRITICAL 9.8
CVE-2021-1870 KEVEPSS 8%

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update…

Fix: 2.30.6 / 10.15.7+
Fix from $2,300 2021-04-02
Fedora MEDIUM 6.5
CVE-2021-1801

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secu…

Fix: 2.30.6 / 7.3+
Fix from $1,600 2021-04-02
Fedora HIGH 8.8
CVE-2021-1789 KEVEPSS 13%

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secu…

Fix: 2.30.6 / 7.3+
Fix from $1,950 2021-04-02
Fedora MEDIUM 6.5
CVE-2021-1765

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secu…

Fix: 2.30.6 / 10.14.6+
Fix from $1,600 2021-04-02
Fedora HIGH 7.5
CVE-2021-29421

models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.

Fix: after 2.9.2
Fix from $1,950 2021-04-01
Fedora MEDIUM 5.3
CVE-2021-22876EPSS 5%

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in …

Fix: after 7.75.0
Fix from $1,600 2021-04-01
Fedora HIGH 8.2
CVE-2021-21332

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.27.0+
Fix from $1,950 2021-03-26
Fedora MEDIUM 6.1
CVE-2021-21333

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.27.0+
Fix from $1,600 2021-03-26
Fedora MEDIUM 5.5
CVE-2021-3467

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format d…

Fix: 2.0.26+
Fix from $1,600 2021-03-25
Fedora CRITICAL 9.8
CVE-2019-10196

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor with…

Fix: 2.1.0+
Fix from $2,300 2021-03-19
Fedora HIGH 7.5
CVE-2021-28831

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentatio…

Fix: after 1.32.1
Fix from $1,950 2021-03-19
Fedora HIGH 7.5
CVE-2021-28089

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

Fix: 0.3.5.14 / 0.4.4.8+
Fix from $1,950 2021-03-19