Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.6
CVE-2024-25713

yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free …

Fix: after 0.8.0
Fix from $1,950 2024-02-29
Fedora MEDIUM 6.1
CVE-2024-27285

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) a…

Fix: 0.9.36+
Fix from $1,600 2024-02-28
Fedora HIGH 7.5
CVE-2024-27507

libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.

No fix yet
Fix from $1,950 2024-02-27
Fedora HIGH 7.5
CVE-2024-25711

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclos…

Fix: 256+
Fix from $1,950 2024-02-27
Fedora HIGH 8.1
CVE-2024-23839

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially craf…

Fix: 7.0.3+
Fix from $1,950 2024-02-26
Fedora MEDIUM 5.3
CVE-2024-24568

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules insp…

Fix: 7.0.3+
Fix from $1,600 2024-02-26
Fedora HIGH 7.5
CVE-2024-23835

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excess…

Fix: 7.0.3+
Fix from $1,950 2024-02-26
Fedora HIGH 7.5
CVE-2024-23836

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.…

Fix: 6.0.16 / 7.0.3+
Fix from $1,950 2024-02-26
Fedora HIGH 7.5
CVE-2024-23837

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of se…

Fix: 0.5.46+
Fix from $1,950 2024-02-26
Fedora HIGH 7.5
CVE-2024-1622

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.

Fix: 0.13.2+
Fix from $1,950 2024-02-26
Fedora MEDIUM 5.3
CVE-2024-21501

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allo…

Fix: 2.12.1+
Fix from $1,600 2024-02-24
Fedora CRITICAL 9.1
CVE-2024-27319

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an o…

Fix: 1.16.0+
Fix from $2,300 2024-02-23
Fedora HIGH 7.5
CVE-2024-27318

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can hav…

Fix: 1.16.0+
Fix from $1,950 2024-02-23
Fedora MEDIUM 5.5
CVE-2024-25629

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc…

Fix: 1.27.0+
Fix from $1,600 2024-02-23
Fedora HIGH 7.5
CVE-2023-3966

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invali…

Fix: 3.1.0+
Fix from $1,950 2024-02-22
Fedora HIGH 7.5
CVE-2024-24476

A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(…

Fix: 4.2.0+
Fix from $1,950 2024-02-21
Fedora CRITICAL 9.8
CVE-2024-23809

A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0…

No fix yet
Fix from $2,300 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-23310

A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A spe…

No fix yet
Fix from $2,300 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-23313

An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A…

No fix yet
Fix from $2,300 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-23606

An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111).…

No fix yet
Fix from $2,300 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-21795

A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111…

No fix yet
Fix from $2,300 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-21812

An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A …

No fix yet
Fix from $2,300 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-22097

A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0…

No fix yet
Fix from $2,300 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-23305

An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (a…

No fix yet
Fix from $2,300 2024-02-20
Fedora HIGH 7.5
CVE-2023-4408

The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS …

Fix: after 9.19.19
Fix from $1,950 2024-02-13
Fedora HIGH 7.5
CVE-2023-5517

A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured,…

Fix: after 9.19.19
Fix from $1,950 2024-02-13
Fedora HIGH 7.5
CVE-2023-5679

A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these …

Fix: after 9.19.19
Fix from $1,950 2024-02-13
Fedora MEDIUM 5.3
CVE-2023-6681

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and d…

Fix: 1.5.1+
Fix from $1,600 2024-02-12
Fedora HIGH 7.8
CVE-2024-0229

An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a…

Fix: 21.1.11 / 23.2.4+
Fix from $1,950 2024-02-09
Fedora HIGH 7.8
CVE-2024-22667

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down…

Fix: 9.0.2142+
Fix from $1,950 2024-02-05