Search

Found 16,785 results in 1431ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-44900 unknown FIX debian debian 4y ago A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z fil…
CVE-2022-4262 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-37533 unknown FIX slesdebian debian 4y ago Apache Commons Net vulnerable to information leakage via malicious server
CVE-2022-46146 unknown FIX slesdebian debian 4y ago Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypa…
CVE-2022-46149 unknown FIX debian debian sles 4y ago Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementatio…
CVE-2022-45907 unknown FIX debian debian 4y ago In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CVE-2022-4135 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML p…
CVE-2022-4065 unknown FIX slesdebian debian 4y ago TestNG is vulnerable to Path Traversal
CVE-2022-45047 critical 9.8 9.8 FIX debian debian apache 4y ago Unsafe deserialization in Apache MINA SSHD
CVE-2022-45136 unknown FIX debian debian 4y ago Apache Jena vulnerable to Deserialization of Untrusted Data
CVE-2022-41854 unknown FIX slesdebian debian 4y ago Snakeyaml vulnerable to Stack overflow leading to denial of service
CVE-2022-42964 unknown FIX debian debian 4y ago An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method
CVE-2022-42252 unknown FIX slesdebian debian 4y ago If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default f…
CVE-2022-3723 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-39327 unknown FIX debian debian sles 4y ago Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting ma…
CVE-2022-42890 unknown FIX debian debian sles 4y ago Untrusted code execution in Apache XML Graphics Batik
CVE-2022-41704 unknown FIX debian debian sles 4y ago Apache XML Graphics Batik vulnerable to code execution via SVG.
CVE-2021-3493 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2022-42969 unknown slesdebian debian 4y ago Withdrawn Advisory: ReDoS in py library when used with subversion
CVE-2022-41404 unknown FIX debian debian 4y ago org.ini4j allows attackers to cause a Denial of Service (DoS)
CVE-2022-40664 unknown debian debian 4y ago Apache Shiro Authentication Bypass vulnerability
CVE-2020-26269 critical 9.5 FIX arch archdebian debian 4y ago In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the direc…
CVE-2020-15115 unknown FIX slesdebian debian 4y ago etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess …
CVE-2020-15112 unknown FIX slesdebian debian 4y ago In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are b…
CVE-2020-15106 unknown FIX slesdebian debian 4y ago In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on …
CVE-2022-39237 unknown FIX debian debian 4y ago syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) us…
CVE-2022-41853 unknown FIX slesdebian debian 4y ago HyperSQL DataBase vulnerable to remote code execution when processing untrusted input
CVE-2022-39269 critical 9.1 9.1 FIX debian debian teluu 4y ago PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SR…
CVE-2022-3171 unknown FIX slesdebian debian 4y ago protobuf-java has a potential Denial of Service issue
CVE-2021-43980 unknown FIX slesdebian debian 4y ago The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in …
CVE-2022-39261 unknown FIX debian debian 4y ago Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a us…
CVE-2022-36944 unknown FIX slesdebian debian 4y ago Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization
CVE-2022-40146 unknown FIX debian debian sles 4y ago Apache Batik vulnerable to Server-Side Request Forgery
CVE-2022-38648 unknown FIX debian debian sles 4y ago Apache Batik vulnerable to Server-Side Request Forgery
CVE-2022-38398 unknown FIX debian debian sles 4y ago Apache Batik Server-Side Request Forgery
CVE-2022-40152 unknown slesdebian debian 4y ago Denial of Service due to parser crash
CVE-2022-40150 unknown FIX slesdebian debian 4y ago Jettison memory exhaustion
CVE-2022-40149 unknown FIX debian debian 4y ago Jettison parser crash by stackoverflow
CVE-2022-36109 unknown FIX debian debian sles 4y ago Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has di…
CVE-2022-36056 unknown FIX debian debian 4y ago Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-bl…
CVE-2022-36113 unknown FIX debian debian sles 4y ago Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to the Rust projects it…
CVE-2022-36114 unknown FIX debian debian sles 4y ago Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternat…
CVE-2013-6282 unknown 2.5 KEVEXPFIX debian debian 4y ago The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory whi…
CVE-2013-2596 unknown 1.5 KEVFIX debian debian 4y ago Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.
CVE-2013-2094 unknown 2.5 KEVEXPFIX debian debian 4y ago Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for pri…
CVE-2022-3075 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a craf…
CVE-2021-43565 unknown FIX slesdebian debian 4y ago The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
CVE-2022-36033 unknown FIX slesdebian debian 4y ago jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabled
CVE-2022-0084 unknown FIX debian debian 4y ago XNIO `notifyReadClosed` method logging message to unexpected end
CVE-2021-42521 unknown FIX debian debian 4y ago There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', …
CVE-2022-2294 unknown 1.5 KEVFIX debian debian 4y ago WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerab…
CVE-2022-35948 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically…
CVE-2022-35949 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option…
CVE-2022-2856 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability…
CVE-2022-36359 unknown FIX arch arch slesdebian debian 4y ago An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-D…
CVE-2022-35929 unknown FIX debian debian sles 4y ago cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used with the `--type` fl…
CVE-2022-30333 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-2053 unknown FIX debian debian 4y ago Undertow vulnerable to Dos via Large AJP request
CVE-2022-37394 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and…
CVE-2021-41556 critical 10.0 10.0 debian debianfedora fedora squirrel-lang 4y ago sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel …
CVE-2022-31151 unknown FIX slesdebian debian 4y ago Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users us…
CVE-2022-31150 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0…
CVE-2020-7677 unknown FIX debian debian 4y ago thenify before 3.3.1 made use of unsafe calls to `eval`.
CVE-2021-3859 unknown FIX debian debian 4y ago Undertow vulnerable to Denial of Service (DoS) attacks
CVE-2021-3690 unknown FIX debian debian 4y ago Undertow vulnerable to memory exhaustion due to buffer leak
CVE-2020-10650 unknown FIX slesdebian debian 4y ago jackson-databind vulnerable to unsafe deserialization
CVE-2022-31160 unknown FIX slesdebian debian 4y ago jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
CVE-2022-32224 critical 9.8 9.8 FIX rocky slesdebian debian activerecord_project 4y ago Active Record RCE bug with Serialized Columns
CVE-2022-2048 unknown FIX slesdebian debian 4y ago Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service
CVE-2022-2191 unknown FIX slesdebian debian 4y ago Jetty SslConnection does not release pooled ByteBuffers in case of errors
CVE-2022-2047 unknown FIX slesdebian debian 4y ago Jetty invalid URI parsing may produce invalid HttpURI.authority
CVE-2022-34835 critical 9.8 9.8 FIX slesdebian debian denx 4y ago In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md …
CVE-2022-32532 unknown debian debian 4y ago Improper Authorization in Apache Shiro
CVE-2022-33879 unknown slesdebian debian 4y ago Apache Tika contains incomplete fix for regex DoS
CVE-2022-34305 unknown FIX slesdebian debian 4y ago In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data with…
CVE-2022-31091 unknown FIX arch archdebian debian 4y ago Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI wit…
CVE-2022-31090 unknown FIX arch archdebian debian 4y ago Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` op…
CVE-2022-32210 unknown FIX slesdebian debian 4y ago `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and i…
CVE-2022-31043 unknown FIX arch archdebian debian 4y ago Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds w…
CVE-2022-31042 unknown FIX arch archdebian debian 4y ago Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with…
CVE-2019-5825 unknown 2.5 KEVEXPFIX debian debian 4y ago Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2018-17480 critical 10.0 KEVFIX arch archdebian debian 4y ago Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple w…
CVE-2022-30973 unknown FIX slesdebian debian 4y ago Regular expression denial of service in apache tika
CVE-2022-1802 critical 9.5 FIX arch arch rhel sles 4y ago If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged cont…
CVE-2022-1529 critical 9.5 FIX arch arch rhel sles 4y ago An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled Ja…
CVE-2022-29248 unknown FIX arch archdebian debian 4y ago Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the …
CVE-2021-3629 unknown FIX debian debian 4y ago Undertow Uncontrolled Resource Consumption
CVE-2021-3597 unknown FIX debian debian 4y ago undertow Race Condition vulnerability
CVE-2015-4495 unknown 2.5 KEVEXPFIX debian debian 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2014-3153 unknown 2.5 KEVEXPFIX debian debian 4y ago The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
CVE-2021-20328 unknown FIX debian debian 4y ago Improper Certificate Validation in MongoDB
CVE-2019-17560 unknown FIX debian debian 4y ago Improper Certificate Validation in Apache Netbeans
CVE-2013-5123 unknown 1.0 EXPFIX slesdebian debian 4y ago The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVE-2019-12401 unknown FIX debian debian 4y ago Apache Solr vulnerable to XML Bomb
CVE-2022-29173 unknown FIX debian debian 4y ago go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, …
CVE-2021-22096 unknown debian debian 4y ago Improper Output Neutralization for Logs in Spring Framework
CVE-2021-40797 unknown FIX slesdebian debian 4y ago An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authentic…
CVE-2021-40085 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
CVE-2021-38598 unknown FIX slesdebian debian 4y ago OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending c…
CVE-2021-38155 unknown FIX slesdebian debian 4y ago OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). …