Search

Found 15,713 results in 2092ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-41966 unknown FIX slesdebian debian 4y ago XStream can cause Denial of Service via stack overflow
CVE-2022-45693 unknown FIX slesdebian debian 4y ago Jettison Out-of-bounds Write vulnerability
CVE-2022-45685 unknown FIX slesdebian debian 4y ago Jettison Out-of-bounds Write vulnerability
CVE-2022-41915 unknown FIX slesdebian debian 4y ago Netty vulnerable to HTTP Response splitting from assigning header value iterator
CVE-2022-41881 unknown FIX slesdebian debian 4y ago HAProxyMessageDecoder Stack Exhaustion DoS
CVE-2022-3510 unknown FIX slesdebian debian 4y ago Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVE-2022-3509 unknown FIX slesdebian debian 4y ago Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVE-2022-23491 unknown FIX slesdebian debian 4y ago Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates fro…
CVE-2022-44900 unknown FIX debian debian 4y ago A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z fil…
CVE-2022-4262 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-37533 unknown FIX slesdebian debian 4y ago Apache Commons Net vulnerable to information leakage via malicious server
CVE-2022-46146 unknown FIX slesdebian debian 4y ago Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypa…
CVE-2022-46149 unknown FIX debian debian sles 4y ago Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementatio…
CVE-2022-45907 unknown FIX debian debian 4y ago In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CVE-2022-4135 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML p…
CVE-2022-4065 unknown FIX slesdebian debian 4y ago TestNG is vulnerable to Path Traversal
CVE-2022-2990 low 2.5 FIX rhel rocky sles 4y ago RHSA-2022:7822: container-tools:rhel8 security, bug fix, and enhancement update (Low)
CVE-2022-24736 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-24735 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-23645 low 2.5 FIX rhel rockydebian debian 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-2211 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-1122 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7645: openjpeg2 security update (Low)
CVE-2022-0897 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2021-46195 low 2.5 FIX rheldebian debian sles 4y ago Low: mingw-gcc security and bug fix update
CVE-2021-44269 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7558: wavpack security update (Low)
CVE-2021-3507 low 2.5 FIX rhel sles rocky 4y ago A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers fr…
CVE-2020-23903 low 2.5 FIX rhelarch arch sles 4y ago Low: speex security update
CVE-2022-45136 unknown FIX debian debian 4y ago Apache Jena vulnerable to Deserialization of Untrusted Data
CVE-2022-41854 unknown FIX slesdebian debian 4y ago Snakeyaml vulnerable to Stack overflow leading to denial of service
CVE-2022-42964 unknown FIX debian debian 4y ago An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method
CVE-2022-42252 unknown FIX slesdebian debian 4y ago If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default f…
CVE-2022-3723 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-39327 unknown FIX debian debian sles 4y ago Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting ma…
CVE-2022-42890 unknown FIX debian debian sles 4y ago Untrusted code execution in Apache XML Graphics Batik
CVE-2022-41704 unknown FIX debian debian sles 4y ago Apache XML Graphics Batik vulnerable to code execution via SVG.
CVE-2021-3493 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2022-39399 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2022:7012: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-21624 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-21619 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-42969 unknown slesdebian debian 4y ago Withdrawn Advisory: ReDoS in py library when used with subversion
CVE-2022-41404 unknown FIX debian debian 4y ago org.ini4j allows attackers to cause a Denial of Service (DoS)
CVE-2022-40664 unknown debian debian 4y ago Apache Shiro Authentication Bypass vulnerability
CVE-2022-3358 low 3.5 EXPFIX rhel slesdebian debian 4y ago Low: openssl security and bug fix update
CVE-2020-15115 unknown FIX slesdebian debian 4y ago etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess …
CVE-2020-15112 unknown FIX slesdebian debian 4y ago In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are b…
CVE-2020-15106 unknown FIX slesdebian debian 4y ago In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on …
CVE-2022-39237 unknown FIX debian debian 4y ago syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) us…
CVE-2022-41853 unknown FIX slesdebian debian 4y ago HyperSQL DataBase vulnerable to remote code execution when processing untrusted input
CVE-2022-3171 unknown FIX slesdebian debian 4y ago protobuf-java has a potential Denial of Service issue
CVE-2021-43980 unknown FIX slesdebian debian 4y ago The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in …
CVE-2022-39261 unknown FIX debian debian 4y ago Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a us…
CVE-2022-36944 unknown FIX slesdebian debian 4y ago Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization
CVE-2022-40146 unknown FIX debian debian sles 4y ago Apache Batik vulnerable to Server-Side Request Forgery
CVE-2022-38648 unknown FIX debian debian sles 4y ago Apache Batik vulnerable to Server-Side Request Forgery
CVE-2022-38398 unknown FIX debian debian sles 4y ago Apache Batik Server-Side Request Forgery
CVE-2022-40152 unknown slesdebian debian 4y ago Denial of Service due to parser crash
CVE-2022-40150 unknown FIX slesdebian debian 4y ago Jettison memory exhaustion
CVE-2022-40149 unknown FIX debian debian 4y ago Jettison parser crash by stackoverflow
CVE-2022-36109 unknown FIX debian debian sles 4y ago Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has di…
CVE-2022-36056 unknown FIX debian debian 4y ago Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-bl…
CVE-2022-36113 unknown FIX debian debian sles 4y ago Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to the Rust projects it…
CVE-2022-36114 unknown FIX debian debian sles 4y ago Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternat…
CVE-2013-6282 unknown 2.5 KEVEXPFIX debian debian 4y ago The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory whi…
CVE-2013-2596 unknown 1.5 KEVFIX debian debian 4y ago Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.
CVE-2013-2094 unknown 2.5 KEVEXPFIX debian debian 4y ago Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for pri…
CVE-2022-3075 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a craf…
CVE-2021-43565 unknown FIX slesdebian debian 4y ago The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
CVE-2022-36033 unknown FIX slesdebian debian 4y ago jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabled
CVE-2022-0084 unknown FIX debian debian 4y ago XNIO `notifyReadClosed` method logging message to unexpected end
CVE-2021-42521 unknown FIX debian debian 4y ago There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', …
CVE-2022-2294 unknown 1.5 KEVFIX debian debian 4y ago WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerab…
CVE-2022-35948 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically…
CVE-2022-35949 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option…
CVE-2022-2856 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability…
CVE-2022-36359 unknown FIX arch arch slesdebian debian 4y ago An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-D…
CVE-2022-35929 unknown FIX debian debian sles 4y ago cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used with the `--type` fl…
CVE-2022-30333 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-2053 unknown FIX debian debian 4y ago Undertow vulnerable to Dos via Large AJP request
CVE-2022-37394 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and…
CVE-2022-31151 unknown FIX slesdebian debian 4y ago Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users us…
CVE-2022-31150 unknown FIX slesdebian debian 4y ago undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0…
CVE-2020-7677 unknown FIX debian debian 4y ago thenify before 3.3.1 made use of unsafe calls to `eval`.
CVE-2021-3859 unknown FIX debian debian 4y ago Undertow vulnerable to Denial of Service (DoS) attacks
CVE-2021-3690 unknown FIX debian debian 4y ago Undertow vulnerable to memory exhaustion due to buffer leak
CVE-2020-10650 unknown FIX slesdebian debian 4y ago jackson-databind vulnerable to unsafe deserialization
CVE-2022-31160 unknown FIX slesdebian debian 4y ago jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
CVE-2022-2048 unknown FIX slesdebian debian 4y ago Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service
CVE-2022-2191 unknown FIX slesdebian debian 4y ago Jetty SslConnection does not release pooled ByteBuffers in case of errors
CVE-2022-2047 unknown FIX slesdebian debian 4y ago Jetty invalid URI parsing may produce invalid HttpURI.authority
CVE-2022-32532 unknown debian debian 4y ago Improper Authorization in Apache Shiro
CVE-2022-33879 unknown slesdebian debian 4y ago Apache Tika contains incomplete fix for regex DoS
CVE-2022-34305 unknown FIX slesdebian debian 4y ago In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data with…
CVE-2020-13950 low 2.5 FIX debian debianarch arch sles 4y ago Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, le…
CVE-2022-31091 unknown FIX arch archdebian debian 4y ago Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI wit…
CVE-2022-31090 unknown FIX arch archdebian debian 4y ago Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` op…
CVE-2022-32210 unknown FIX slesdebian debian 4y ago `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and i…
CVE-2022-31043 unknown FIX arch archdebian debian 4y ago Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds w…
CVE-2022-31042 unknown FIX arch archdebian debian 4y ago Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with…
CVE-2019-5825 unknown 2.5 KEVEXPFIX debian debian 4y ago Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2022-30973 unknown FIX slesdebian debian 4y ago Regular expression denial of service in apache tika