Search

Found 14,393 results in 664ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-36114 unknown FIX debian debian sles 4y ago Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternat…
CVE-2013-6282 unknown 2.5 KEVEXPFIX debian debian 4y ago The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory whi…
CVE-2013-2596 unknown 1.5 KEVFIX debian debian 4y ago Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.
CVE-2013-2094 unknown 2.5 KEVEXPFIX debian debian 4y ago Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for pri…
CVE-2022-3075 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a craf…
CVE-2021-43565 unknown FIX slesdebian debian 4y ago The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
CVE-2022-36033 unknown FIX slesdebian debian 4y ago jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabled
CVE-2022-0084 unknown FIX debian debian 4y ago XNIO `notifyReadClosed` method logging message to unexpected end
CVE-2021-42521 unknown FIX debian debian 4y ago There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', …
CVE-2022-2294 unknown 1.5 KEVFIX debian debian 4y ago WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerab…
CVE-2022-35948 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically…
CVE-2022-35949 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option…
CVE-2022-2856 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability…
CVE-2022-36359 unknown FIX arch arch slesdebian debian 4y ago An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-D…
CVE-2022-35929 unknown FIX debian debian sles 4y ago cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used with the `--type` fl…
CVE-2022-30333 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-2053 unknown FIX debian debian 4y ago Undertow vulnerable to Dos via Large AJP request
CVE-2022-37394 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and…
CVE-2022-31151 unknown FIX slesdebian debian 4y ago Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users us…
CVE-2022-31150 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0…
CVE-2020-7677 unknown FIX debian debian 4y ago thenify before 3.3.1 made use of unsafe calls to `eval`.
CVE-2021-3859 unknown FIX debian debian 4y ago Undertow vulnerable to Denial of Service (DoS) attacks
CVE-2021-3690 unknown FIX debian debian 4y ago Undertow vulnerable to memory exhaustion due to buffer leak
CVE-2020-10650 unknown FIX slesdebian debian 4y ago jackson-databind vulnerable to unsafe deserialization
CVE-2022-31160 unknown FIX slesdebian debian 4y ago jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
CVE-2022-2048 unknown FIX slesdebian debian 4y ago Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service
CVE-2022-2191 unknown FIX slesdebian debian 4y ago Jetty SslConnection does not release pooled ByteBuffers in case of errors
CVE-2022-2047 unknown FIX slesdebian debian 4y ago Jetty invalid URI parsing may produce invalid HttpURI.authority
CVE-2022-32532 unknown debian debian 4y ago Improper Authorization in Apache Shiro
CVE-2022-33879 unknown slesdebian debian 4y ago Apache Tika contains incomplete fix for regex DoS
CVE-2022-34305 unknown FIX slesdebian debian 4y ago In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data with…
CVE-2022-31091 unknown FIX arch archdebian debian 4y ago Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI wit…
CVE-2022-31090 unknown FIX arch archdebian debian 4y ago Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` op…
CVE-2022-32210 unknown FIX slesdebian debian 4y ago `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and i…
CVE-2022-31043 unknown FIX arch archdebian debian 4y ago Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds w…
CVE-2022-31042 unknown FIX arch archdebian debian 4y ago Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with…
CVE-2019-5825 unknown 2.5 KEVEXPFIX debian debian 4y ago Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2022-30973 unknown FIX slesdebian debian 4y ago Regular expression denial of service in apache tika
CVE-2022-29248 unknown FIX arch archdebian debian 4y ago Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the …
CVE-2021-3629 unknown FIX debian debian 4y ago Undertow Uncontrolled Resource Consumption
CVE-2021-3597 unknown FIX debian debian 4y ago undertow Race Condition vulnerability
CVE-2015-4495 unknown 2.5 KEVEXPFIX debian debian 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2014-3153 unknown 2.5 KEVEXPFIX debian debian 4y ago The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
CVE-2021-20328 unknown FIX debian debian 4y ago Improper Certificate Validation in MongoDB
CVE-2019-17560 unknown FIX debian debian 4y ago Improper Certificate Validation in Apache Netbeans
CVE-2013-5123 unknown 1.0 EXPFIX slesdebian debian 4y ago The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVE-2019-12401 unknown FIX debian debian 4y ago Apache Solr vulnerable to XML Bomb
CVE-2022-29173 unknown FIX debian debian 4y ago go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, …
CVE-2021-22096 unknown debian debian 4y ago Improper Output Neutralization for Logs in Spring Framework
CVE-2021-40797 unknown FIX slesdebian debian 4y ago An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authentic…
CVE-2021-40085 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
CVE-2021-38598 unknown FIX slesdebian debian 4y ago OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending c…
CVE-2021-38155 unknown FIX slesdebian debian 4y ago OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). …
CVE-2021-20267 unknown FIX slesdebian debian 4y ago A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersona…
CVE-2021-22118 unknown FIX debian debian 4y ago Improper Privilege Management in Spring Framework
CVE-2021-33194 unknown FIX slesdebian debian 4y ago golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
CVE-2020-29582 unknown FIX debian debian 4y ago Incorrect Default Permissions in JetBrains Kotlin
CVE-2020-17376 unknown FIX slesdebian debian 4y ago An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously under…
CVE-2020-12692 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
CVE-2020-12691 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then …
CVE-2020-12689 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escala…
CVE-2020-1745 unknown FIX debian debian 4y ago Improper Authorization in Undertoe
CVE-2020-1757 unknown FIX debian debian 4y ago Improper Input Validation in Undertow
CVE-2019-17561 unknown FIX debian debian 4y ago Improper Verification of Cryptographic Signature in Apache Netbeans
CVE-2015-9543 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs …
CVE-2019-14888 unknown FIX debian debian 4y ago Undertow vulnerable to Uncontrolled Resource Consumption
CVE-2016-1000027 unknown FIX debian debian 4y ago Pivotal Spring Framework contains unsafe Java deserialization methods
CVE-2019-19687 unknown FIX debian debian 4y ago OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enfor…
CVE-2019-0205 unknown FIX slesdebian debian 4y ago Loop with Unreachable Exit Condition in Apache Thrift
CVE-2019-12415 unknown debian debian 4y ago Improper Restriction of XML External Entity Reference in Apache POI
CVE-2019-17091 unknown FIX debian debian 4y ago Cross-site Scripting in Eclipse Mojarra
CVE-2019-0231 unknown FIX debian debian 4y ago Cleartext Transmission of Sensitive Information in Apache MINA
CVE-2019-16370 unknown FIX debian debian 4y ago Use of a weak cryptographic algorithm in Gradle
CVE-2019-14433 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external excepti…
CVE-2019-14271 unknown FIX slesdebian debian 4y ago In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the conten…
CVE-2019-13509 unknown FIX slesdebian debian 4y ago In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a…
CVE-2017-11365 unknown FIX debian debian 4y ago Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The compo…
CVE-2019-11841 unknown FIX debian debian 4y ago A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 488…
CVE-2021-1048 unknown 1.5 KEVFIX slesdebian debian 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2022-24434 unknown FIX debian debian 4y ago Crash in HeaderParser in dicer
CVE-2014-9390 unknown 1.0 EXPFIX debian debian 4y ago Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; …
CVE-2014-9720 unknown FIX debian debian 4y ago Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determi…
CVE-2014-4172 unknown FIX debian debian 4y ago Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
CVE-2012-3442 unknown FIX debian debian 4y ago The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which…
CVE-2022-30126 unknown slesdebian debian 4y ago Regular expression denial of service in apache tika
CVE-2022-25169 unknown slesdebian debian 4y ago Apache Tika vulnerable to uncontrolled memory consumption
CVE-2014-3607 unknown FIX debian debian 4y ago Improper Certificate Validation in vt-ldap
CVE-2018-11407 unknown FIX debian debian 4y ago An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by l…
CVE-2018-14371 unknown FIX debian debian 4y ago Path Traversal in Eclipse Mojarra
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2017-16790 unknown FIX debian debian 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST …
CVE-2008-5619 unknown 1.0 EXPFIX debian debian 4y ago html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attack…
CVE-2016-9606 unknown FIX debian debian 4y ago JBoss RESTEasy vulnerable to Improper Input Validation
CVE-2018-14774 unknown FIX debian debian 4y ago An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using Http…
CVE-2018-1000665 unknown FIX debian debian 4y ago Improper Neutralization of Input During Web Page Generation in Dojo Dojo Objective Harness
CVE-2018-17983 unknown FIX slesdebian debian 4y ago cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.
CVE-2018-7749 unknown FIX debian debian 4y ago The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authe…
CVE-2018-1294 unknown FIX debian debian 4y ago Improper Input Validation Apache Commons Email
CVE-2018-11385 unknown FIX debian debian 4y ago An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerabil…
CVE-2017-16652 unknown FIX debian debian 4y ago An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler t…