Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-25222 A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c. Libredwg No fix yet Fix from $1,9502023-03-01 MEDIUM 5.9 CVE-2023-27371 GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.… Libmicrohttpd 0.9.76+ Fix from $1,6002023-02-28 HIGH 7.8 CVE-2022-48339 An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the para… Emacs after 28.2 Fix from $1,9502023-02-20 HIGH 7.3 CVE-2022-48338 An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. … Emacs after 28.2 Fix from $1,9502023-02-20 CRITICAL 9.8 CVE-2023-0687 A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file g… Glibc 2.38+ Fix from $2,3002023-02-06 CRITICAL 9.8 CVE-2023-25139 sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelate… Glibc No fix yet Fix from $2,3002023-02-03 HIGH 7.8 CVE-2022-45332 LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c. Libredwg No fix yet Fix from $1,9502022-11-30 MEDIUM 6.5 CVE-2022-41550 GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. Osip No fix yet Fix from $1,6002022-10-11 MEDIUM 5.3 CVE-2022-39046 An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads… Glibc No fix yet Fix from $1,6002022-08-31 HIGH 7.5 CVE-2021-3998 A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosu… Glibc 2.35+ Fix from $1,9502022-08-24 CRITICAL 9.8 CVE-2022-35164 LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. Libredwg 0.12.4.4608+ Fix from $2,3002022-08-18 HIGH 7.8 CVE-2022-33025 LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c. Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 7.8 CVE-2022-33026 LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c. Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 7.8 CVE-2022-33027 LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c. Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 7.8 CVE-2022-33028 LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c. Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 7.8 CVE-2022-33032 LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c. Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 7.8 CVE-2022-33033 LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c. Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 7.8 CVE-2022-33034 LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c. Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 7.5 CVE-2022-33024 There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dw… Libredwg No fix yet Fix from $1,9502022-06-23 HIGH 8.8 CVE-2021-42585 A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. Libredwg 0.12.4+ Fix from $1,9502022-05-23 HIGH 8.8 CVE-2021-42586 A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. Libredwg 0.12.4+ Fix from $1,9502022-05-23 MEDIUM 5.5 CVE-2021-46195 GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cau… Gcc No fix yet Fix from $1,6002022-01-14 MEDIUM 6.5 CVE-2021-45950 LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object). Libredwg after 0.12.4.4367 Fix from $1,6002022-01-01 MEDIUM 5.5 CVE-2021-45261 An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service. Patch No fix yet Fix from $1,6002021-12-22 CRITICAL 9.8 CVE-2021-28237 LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13. Libredwg No fix yet Fix from $2,3002021-12-02 HIGH 7.5 CVE-2021-28236 LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c. Libredwg No fix yet Fix from $1,9502021-12-02 HIGH 7.8 CVE-2021-37322 GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c. Binutils 2.32 / 10.1+ Fix from $1,9502021-11-18 HIGH 8.8 CVE-2021-43413 An issue was discovered in GNU Hurd before 0.9 20210404-9. A single pager port is shared among everyone who mmaps a file, allowing anyone to modify a… Hurd 0.9.20210404-9+ Fix from $1,9502021-11-07 HIGH 7.8 CVE-2021-43412 An issue was discovered in GNU Hurd before 0.9 20210404-9. libports accepts fake notification messages from any client on any port, which can lead to… Hurd 0.9.20210404-9+ Fix from $1,9502021-11-07 HIGH 7.5 CVE-2021-43411 An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already… Hurd 0.9.20210404-9+ Fix from $1,9502021-11-07