Search

Found 15,728 results in 867ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-4418 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:4351: virt:rhel and virt-devel:rhel security and bug fix update (Low)
CVE-2024-4032 low 2.5 FIX rhel rocky sles 2y ago Low: python3 security update
CVE-2024-25638 unknown FIX debian debian 2y ago DNSJava DNSSEC Bypass
CVE-2024-40644 unknown FIX debian debian 2y ago gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows…
CVE-2022-48833 unknown FIX slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: skip reserved bytes warning on unmount after log cleanup failure After the recent changes made by commit c2e39305299f01 ("…
CVE-2022-29946 unknown FIX debian debian 2y ago NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one sc…
CVE-2024-39614 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings contain…
CVE-2024-39330 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicati…
CVE-2024-39329 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing a…
CVE-2024-38875 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of br…
CVE-2024-38372 unknown FIX debian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the N…
CVE-2024-3653 unknown FIX debian debian 2y ago Undertow Missing Release of Memory after Effective Lifetime vulnerability
CVE-2024-5971 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2024-39689 unknown FIX slesdebian debian 2y ago Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.…
CVE-2024-32498 unknown FIX debian debian 2y ago An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 …
CVE-2022-30636 unknown FIX debian debian 2y ago httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a di…
CVE-2023-2953 low 2.5 FIX rocky slesdebian debian 2y ago RHSA-2024:4264: openldap security update (Low)
CVE-2024-58261 unknown FIX slesdebian debian 2y ago The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupp…
CVE-2020-13965 unknown 1.5 KEVFIX debian debian 2y ago Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.
CVE-2024-6162 unknown FIX debian debian 2y ago Undertow's url-encoded request path information can be broken on ajp-listener
CVE-2024-38595 unknown FIX slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix peer devlink set for SF representor devlink port The cited patch change register devlink flow, and neglect to refle…
CVE-2024-4577 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CVE-2024-35241 unknown FIX debian debian sles 2y ago Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing …
CVE-2024-35242 unknown FIX debian debian sles 2y ago Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch na…
CVE-2024-37568 unknown FIX slesdebian debian 2y ago lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (…
CVE-2024-5629 low 2.5 FIX rocky slesdebian debian 2y ago RHSA-2025:8419: python36:3.6 security update (Low)
CVE-2015-2309 unknown FIX debian debian 2y ago Symfony has unsafe methods in the Request class
CVE-2024-5274 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Ch…
CVE-2024-35197 unknown FIX slesdebian debian 2y ago gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary…
CVE-2024-35186 unknown FIX slesdebian debian 2y ago gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned…
CVE-2020-21710 low 2.5 FIX slesdebian debian rocky 2y ago RHSA-2024:2966: ghostscript security update (Low)
CVE-2024-4947 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2024-35935 low 3.3 3.3 FIX slesdebian debian linux-kernel 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: send: handle path ref underflow in header iterate_inode_ref() Change BUG_ON to proper error handling if building the path …
CVE-2024-4761 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, includ…
CVE-2024-35176 low 2.5 FIX rocky slesdebian debian 2y ago RHSA-2024:5338: pcs security update (Low)
CVE-2024-30172 unknown FIX debian debian sles 2y ago Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
CVE-2024-30171 unknown FIX debian debian sles 2y ago Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
CVE-2024-29857 unknown FIX debian debian sles 2y ago Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
CVE-2024-4671 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers…
CVE-2024-25629 low 2.5 FIX rheldebian debian rocky 2y ago RHSA-2024:4249: c-ares security update (Low)
CVE-2024-34447 unknown FIX debian debian sles 2y ago Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
CVE-2024-30251 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp serv…
CVE-2024-32114 unknown FIX debian debian 2y ago Apache ActiveMQ's default configuration doesn't secure the API web context
CVE-2024-31573 unknown FIX debian debian 2y ago XMLUnit for Java has Insecure Defaults when Processing XSLT Stylesheets
CVE-2023-6918 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:3233: libssh security update (Low)
CVE-2023-6004 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:3233: libssh security update (Low)
CVE-2023-52620 low 2.5 2.5 FIX rhel rocky sles 2y ago Important: kernel security, bug fix, and enhancement update
CVE-2023-3817 low 2.5 FIX rocky rhel sles 2y ago RHSA-2023:7877: openssl security update (Low)
CVE-2023-3446 low 2.5 FIX rocky rhel sles 2y ago RHSA-2024:0888: edk2 security update (Low)
CVE-2023-32636 low 2.5 FIX rhel slesdebian debian 2y ago Low: mingw-glib2 security update
CVE-2023-2975 low 2.5 FIX rhel slesdebian debian 2y ago Low: openssl and openssl-fips-provider security update
CVE-2023-1729 low 2.5 FIX rhel slesdebian debian 2y ago Low: LibRaw security update
CVE-2022-48554 low 2.5 FIX rheldebian debian rocky 2y ago File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
CVE-2023-46565 unknown FIX slesdebian debian 2y ago Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.
CVE-2024-32887 unknown FIX debian debian 2y ago Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr parameter is reflected in the response without any encoding, allowing an attac…
CVE-2024-32875 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are im…
CVE-2024-31584 unknown FIX debian debian 2y ago Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
CVE-2024-32473 unknown FIX debian debian sles 2y ago Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on netwo…
CVE-2024-27306 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have alway…
CVE-2024-3864 low 2.5 FIX rhel rockydebian debian 2y ago Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited…
CVE-2024-3861 low 2.5 FIX rhel rockydebian debian 2y ago If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 11…
CVE-2024-3859 low 2.5 FIX rhel rockydebian debian 2y ago On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox E…
CVE-2024-3857 low 2.5 FIX rhel rockydebian debian 2y ago The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, …
CVE-2024-3854 low 2.5 FIX rhel rockydebian debian 2y ago In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 11…
CVE-2024-3852 low 2.5 FIX rhel rockydebian debian 2y ago GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVE-2024-3302 low 2.5 FIX rhel rockydebian debian 2y ago There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firef…
CVE-2024-2609 low 2.5 FIX rhel rockydebian debian 2y ago The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR …
CVE-2024-31583 unknown FIX debian debian 2y ago Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
CVE-2024-31580 unknown FIX debian debian 2y ago PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (…
CVE-2024-22262 unknown debian debian 2y ago Spring Framework URL Parsing with Host Validation
CVE-2024-29903 unknown FIX debian debian sles 2y ago Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause denial of service of the machine running Cosign the…
CVE-2024-29902 unknown FIX debian debian sles 2y ago Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cause denial of service of the host machine running C…
CVE-2021-22573 unknown FIX debian debian 2y ago google-oauth-java-client improperly verifies cryptographic signature
CVE-2024-30261 unknown FIX slesdebian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been…
CVE-2024-30260 unknown FIX slesdebian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnera…
CVE-2024-28085 low 3.3 3.3 FIX slesdebian debian kernel 2y ago wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from …
CVE-2024-29025 unknown FIX slesdebian debian 2y ago Netty's HttpPostRequestDecoder can OOM
CVE-2023-5685 unknown debian debian 2y ago XNIO denial of service vulnerability
CVE-2024-29133 unknown FIX debian debian sles 2y ago Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
CVE-2024-29131 unknown FIX debian debian sles 2y ago Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
CVE-2024-29018 unknown FIX debian debian sles 2y ago Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows …
CVE-2024-22259 unknown debian debian 2y ago Spring Framework URL Parsing with Host Validation Vulnerability
CVE-2024-27351 unknown FIX slesdebian debian 2y ago In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a poten…
CVE-2024-23944 unknown FIX debian debian 2y ago Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
CVE-2024-27308 unknown FIX debian debian 2y ago Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to named pipes that have already been deregistered from…
CVE-2024-22871 unknown FIX debian debian 2y ago Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
CVE-2023-51775 unknown FIX slesdebian debian 2y ago jose4j denial of service via specifically crafted JWE
CVE-2024-21742 unknown FIX debian debian 2y ago Apache James MIME4J improper input validation vulnerability
CVE-2024-22201 unknown FIX slesdebian debian 2y ago Connection leaking on idle timeout when TCP congested
CVE-2024-22243 unknown debian debian 2y ago Spring Web vulnerable to Open Redirect or Server Side Request Forgery
CVE-2024-1635 unknown FIX debian debian 2y ago Undertow Uncontrolled Resource Consumption Vulnerability
CVE-2024-26308 unknown FIX slesdebian debian 2y ago Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
CVE-2024-25710 unknown FIX slesdebian debian 2y ago Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
CVE-2024-20925 unknown FIX slesdebian debian 2y ago Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project
CVE-2024-24758 unknown FIX slesdebian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue ha…
CVE-2024-24750 unknown FIX debian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory lea…
CVE-2024-1459 unknown FIX debian debian 2y ago Undertow Path Traversal vulnerability
CVE-2024-24762 unknown FIX slesdebian debian 2y ago `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attack…
CVE-2024-23833 unknown FIX debian debian 2y ago OpenRefine JDBC Attack Vulnerability
CVE-2023-43770 unknown 1.5 KEVFIX debian debian 2y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.