Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libredwg HIGH 8.8
CVE-2023-25222

A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c.

No fix yet
Fix from $1,950 2023-03-01
Libmicrohttpd MEDIUM 5.9
CVE-2023-27371

GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.…

Fix: 0.9.76+
Fix from $1,600 2023-02-28
Emacs HIGH 7.8
CVE-2022-48339

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the para…

Fix: after 28.2
Fix from $1,950 2023-02-20
Emacs HIGH 7.3
CVE-2022-48338

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. …

Fix: after 28.2
Fix from $1,950 2023-02-20
Glibc CRITICAL 9.8
CVE-2023-0687

A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file g…

Fix: 2.38+
Fix from $2,300 2023-02-06
Glibc CRITICAL 9.8
CVE-2023-25139

sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelate…

No fix yet
Fix from $2,300 2023-02-03
Libredwg HIGH 7.8
CVE-2022-45332

LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.

No fix yet
Fix from $1,950 2022-11-30
Osip MEDIUM 6.5
CVE-2022-41550

GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

No fix yet
Fix from $1,600 2022-10-11
Glibc MEDIUM 5.3
CVE-2022-39046

An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads…

No fix yet
Fix from $1,600 2022-08-31
Glibc HIGH 7.5
CVE-2021-3998

A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosu…

Fix: 2.35+
Fix from $1,950 2022-08-24
Libredwg CRITICAL 9.8
CVE-2022-35164

LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.

Fix: 0.12.4.4608+
Fix from $2,300 2022-08-18
Libredwg HIGH 7.8
CVE-2022-33025

LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 7.8
CVE-2022-33026

LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 7.8
CVE-2022-33027

LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 7.8
CVE-2022-33028

LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 7.8
CVE-2022-33032

LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 7.8
CVE-2022-33033

LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 7.8
CVE-2022-33034

LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 7.5
CVE-2022-33024

There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dw…

No fix yet
Fix from $1,950 2022-06-23
Libredwg HIGH 8.8
CVE-2021-42585

A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

Fix: 0.12.4+
Fix from $1,950 2022-05-23
Libredwg HIGH 8.8
CVE-2021-42586

A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

Fix: 0.12.4+
Fix from $1,950 2022-05-23
Gcc MEDIUM 5.5
CVE-2021-46195

GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cau…

No fix yet
Fix from $1,600 2022-01-14
Libredwg MEDIUM 6.5
CVE-2021-45950

LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).

Fix: after 0.12.4.4367
Fix from $1,600 2022-01-01
Patch MEDIUM 5.5
CVE-2021-45261

An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.

No fix yet
Fix from $1,600 2021-12-22
Libredwg CRITICAL 9.8
CVE-2021-28237

LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.

No fix yet
Fix from $2,300 2021-12-02
Libredwg HIGH 7.5
CVE-2021-28236

LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.

No fix yet
Fix from $1,950 2021-12-02
Binutils HIGH 7.8
CVE-2021-37322

GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.

Fix: 2.32 / 10.1+
Fix from $1,950 2021-11-18
Hurd HIGH 8.8
CVE-2021-43413

An issue was discovered in GNU Hurd before 0.9 20210404-9. A single pager port is shared among everyone who mmaps a file, allowing anyone to modify a…

Fix: 0.9.20210404-9+
Fix from $1,950 2021-11-07
Hurd HIGH 7.8
CVE-2021-43412

An issue was discovered in GNU Hurd before 0.9 20210404-9. libports accepts fake notification messages from any client on any port, which can lead to…

Fix: 0.9.20210404-9+
Fix from $1,950 2021-11-07
Hurd HIGH 7.5
CVE-2021-43411

An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already…

Fix: 0.9.20210404-9+
Fix from $1,950 2021-11-07