Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libyang HIGH 7.5
CVE-2023-26917

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.

Fix: after 2.1.30
Fix from $1,950 2023-04-11
Theme Cesnet MEDIUM 5.5
CVE-2016-15014

A vulnerability has been found in CESNET theme-cesnet up to 1.x on ownCloud and classified as problematic. Affected by this vulnerability is an unkno…

Fix: 2.0.0+
Fix from $1,600 2023-01-07
Libyang HIGH 7.5
CVE-2021-28902

In function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL,…

Fix: after 1.0.225
Fix from $1,950 2021-05-20
Libyang HIGH 7.5
CVE-2021-28903

A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_elem() function will be called …

Fix: after 1.0.225
Fix from $1,950 2021-05-20
Libyang HIGH 7.5
CVE-2021-28904

In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULL. If revision is NULL, the operation of st…

Fix: after 1.0.225
Fix from $1,950 2021-05-20
Libyang HIGH 7.5
CVE-2021-28905

In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL. But in some cases, node->module can be n…

Fix: after 1.0.225
Fix from $1,950 2021-05-20
Libyang HIGH 7.5
CVE-2021-28906

In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, whic…

Fix: after 1.0.225
Fix from $1,950 2021-05-20
Perun HIGH 7.5
CVE-2020-5281

In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAP. Issue is fixed in …

Fix: 3.9.1+
Fix from $1,950 2020-03-25
Libyang HIGH 8.8
CVE-2019-20393

A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to pars…

Patch available
Fix from $1,950 2020-01-22
Libyang HIGH 8.8
CVE-2019-20394

A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications …

Patch available
Fix from $1,950 2020-01-22
Libyang HIGH 8.8
CVE-2019-20397

A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use liby…

Patch available
Fix from $1,950 2020-01-22
Libyang MEDIUM 6.5
CVE-2019-20391

An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is used insid…

Patch available
Fix from $1,600 2020-01-22
Libyang MEDIUM 6.5
CVE-2019-20392

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used insid…

Patch available
Fix from $1,600 2020-01-22
Libyang MEDIUM 6.5
CVE-2019-20395

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use liby…

Patch available
Fix from $1,600 2020-01-22
Libyang MEDIUM 6.5
CVE-2019-20396

A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lys_parse_path parsing.

Patch available
Fix from $1,600 2020-01-22
Libyang MEDIUM 6.5
CVE-2019-20398

A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a copy of unresolved extensions…

Patch available
Fix from $1,600 2020-01-22
Proxystatistics CRITICAL 9.8
CVE-2019-15537

The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.

Fix: 3.1.0+
Fix from $2,300 2019-08-23