Search

Found 16,776 results in 924ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-22118 unknown FIX debian debian 4y ago Improper Privilege Management in Spring Framework
CVE-2021-33194 unknown FIX slesdebian debian 4y ago golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
CVE-2020-29582 unknown FIX debian debian 4y ago Incorrect Default Permissions in JetBrains Kotlin
CVE-2020-17376 unknown FIX slesdebian debian 4y ago An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously under…
CVE-2020-12692 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
CVE-2020-12691 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then …
CVE-2020-12689 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escala…
CVE-2020-1745 unknown FIX debian debian 4y ago Improper Authorization in Undertoe
CVE-2020-1757 unknown FIX debian debian 4y ago Improper Input Validation in Undertow
CVE-2019-17561 unknown FIX debian debian 4y ago Improper Verification of Cryptographic Signature in Apache Netbeans
CVE-2015-9543 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs …
CVE-2019-14888 unknown FIX debian debian 4y ago Undertow vulnerable to Uncontrolled Resource Consumption
CVE-2016-1000027 unknown FIX debian debian 4y ago Pivotal Spring Framework contains unsafe Java deserialization methods
CVE-2019-19687 unknown FIX debian debian 4y ago OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enfor…
CVE-2019-0205 unknown FIX slesdebian debian 4y ago Loop with Unreachable Exit Condition in Apache Thrift
CVE-2019-12415 unknown debian debian 4y ago Improper Restriction of XML External Entity Reference in Apache POI
CVE-2019-17091 unknown FIX debian debian 4y ago Cross-site Scripting in Eclipse Mojarra
CVE-2019-0231 unknown FIX debian debian 4y ago Cleartext Transmission of Sensitive Information in Apache MINA
CVE-2019-16370 unknown FIX debian debian 4y ago Use of a weak cryptographic algorithm in Gradle
CVE-2019-14433 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external excepti…
CVE-2019-14271 unknown FIX slesdebian debian 4y ago In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the conten…
CVE-2019-13509 unknown FIX slesdebian debian 4y ago In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a…
CVE-2017-11365 unknown FIX debian debian 4y ago Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The compo…
CVE-2019-11841 unknown FIX debian debian 4y ago A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 488…
CVE-2019-5815 critical 9.5 FIX arch archdebian debian 4y ago Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
CVE-2021-1048 unknown 1.5 KEVFIX slesdebian debian 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2019-13720 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11707 critical 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2022-24434 unknown FIX debian debian 4y ago Crash in HeaderParser in dicer
CVE-2014-9390 unknown 1.0 EXPFIX debian debian 4y ago Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; …
CVE-2014-9720 unknown FIX debian debian 4y ago Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determi…
CVE-2014-4172 unknown FIX debian debian 4y ago Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
CVE-2012-3442 unknown FIX debian debian 4y ago The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which…
CVE-2022-30126 unknown slesdebian debian 4y ago Regular expression denial of service in apache tika
CVE-2022-25169 unknown slesdebian debian 4y ago Apache Tika vulnerable to uncontrolled memory consumption
CVE-2014-3607 unknown FIX debian debian 4y ago Improper Certificate Validation in vt-ldap
CVE-2018-11407 unknown FIX debian debian 4y ago An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by l…
CVE-2018-14371 unknown FIX debian debian 4y ago Path Traversal in Eclipse Mojarra
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2017-16790 unknown FIX debian debian 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST …
CVE-2008-5619 unknown 1.0 EXPFIX debian debian 4y ago html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attack…
CVE-2016-9606 unknown FIX debian debian 4y ago JBoss RESTEasy vulnerable to Improper Input Validation
CVE-2018-14774 unknown FIX debian debian 4y ago An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using Http…
CVE-2015-8914 critical 9.1 9.1 FIX slesdebian debian openstack 4y ago The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of s…
CVE-2018-1000665 unknown FIX debian debian 4y ago Improper Neutralization of Input During Web Page Generation in Dojo Dojo Objective Harness
CVE-2018-17983 unknown FIX slesdebian debian 4y ago cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.
CVE-2018-7749 unknown FIX debian debian 4y ago The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authe…
CVE-2018-1294 unknown FIX debian debian 4y ago Improper Input Validation Apache Commons Email
CVE-2018-11385 unknown FIX debian debian 4y ago An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerabil…
CVE-2018-5158 critical 9.5 FIX arch archdebian debian 4y ago The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permis…
CVE-2017-16652 unknown FIX debian debian 4y ago An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler t…
CVE-2017-16654 unknown FIX debian debian 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the …
CVE-2018-11408 unknown FIX debian debian 4y ago The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnera…
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2018-19859 unknown FIX debian debian 4y ago OpenRefine Directory Traversal
CVE-2018-11386 unknown FIX debian debian 4y ago An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler c…
CVE-2018-11406 unknown FIX debian debian 4y ago An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session …
CVE-2017-15706 unknown FIX slesdebian debian 4y ago As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorit…
CVE-2016-6810 unknown FIX debian debian 4y ago Improper Neutralization of Input During Web Page Generation Apache ActiveMQ
CVE-2018-19790 unknown FIX debian debian 4y ago An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_f…
CVE-2018-19789 unknown FIX debian debian 4y ago An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `strin…
CVE-2017-15691 unknown FIX debian debian 4y ago Improper Restriction of XML External Entity Reference in Apache uimaj
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2017-1000190 unknown FIX debian debian 4y ago SimpleXML has XML External Entity (XXE) vulnerability
CVE-2018-1000079 unknown FIX slesdebian debian 4y ago RubyGems Path Traversal vulnerability
CVE-2018-1000078 unknown FIX slesdebian debian 4y ago RubyGems Cross-site Scripting vulnerability
CVE-2018-1000077 unknown FIX slesdebian debian 4y ago RubyGems Improper Input Validation vulnerability
CVE-2018-1000076 unknown FIX slesdebian debian 4y ago RubyGems Improper Verification of Cryptographic Signature vulnerability
CVE-2018-1000074 unknown FIX slesdebian debian 4y ago RubyGems Deserialization of Untrusted Data vulnerability
CVE-2017-1000426 unknown FIX debian debian 4y ago MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.
CVE-2018-8036 unknown FIX slesdebian debian 4y ago Loop with Unreachable Exit Condition in Apache PDFBox
CVE-2018-1297 unknown debian debian 4y ago Missing certificate validation in Apache JMeter
CVE-2018-1287 unknown debian debian 4y ago Missing certificate validation in Apache JMeter
CVE-2017-18191 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt t…
CVE-2017-16653 unknown FIX debian debian 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different token…
CVE-2017-1000116 critical 9.8 9.8 FIX arch arch slesdebian debian mercurial 4y ago Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVE-2017-12165 unknown FIX debian debian 4y ago Undertow Request Smuggling vulnerability
CVE-2017-12196 unknown FIX debian debian 4y ago Incorrect Authorization in Undertow
CVE-2017-7559 unknown FIX debian debian 4y ago Undertow vulnerable to Request Smuggling
CVE-2018-1002202 unknown FIX debian debian 4y ago Improper Limitation of a Pathname to a Restricted Directory in Zip4j
CVE-2018-1002200 unknown FIX debian debian 4y ago Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver
CVE-2018-14636 unknown FIX slesdebian debian 4y ago Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively…
CVE-2018-1051 unknown FIX debian debian 4y ago Deserialization of Untrusted Data in org.jboss.resteasy:resteasy-yaml-provider
CVE-2018-1114 unknown FIX debian debian 4y ago Uncontrolled Resource Consumption in Undertow
CVE-2016-6814 unknown FIX debian debian 4y ago Deserialization of Untrusted Data in Groovy
CVE-2017-17458 critical 9.8 9.8 FIX slesdebian debian mercurial 4y ago In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the rep…
CVE-2018-13348 unknown FIX slesdebian debian 4y ago The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actu…
CVE-2018-13347 unknown FIX slesdebian debian 4y ago mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.
CVE-2018-13346 unknown FIX slesdebian debian 4y ago The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
CVE-2018-1000132 unknown FIX slesdebian debian 4y ago Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via …
CVE-2019-11065 unknown FIX debian debian 4y ago Insecure transport protocol in Gradle
CVE-2016-8735 unknown 1.5 KEVFIX slesdebian debian 4y ago Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This C…
CVE-2018-1067 unknown FIX debian debian 4y ago Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
CVE-2019-3830 unknown FIX debian debian sles 4y ago A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
CVE-2018-1048 unknown FIX debian debian 4y ago Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
CVE-2018-14642 unknown FIX debian debian 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Undertow
CVE-2017-1000487 unknown FIX debian debian 4y ago OS Command Injection in Plexus-utils
CVE-2017-15709 unknown FIX debian debian 4y ago ActiveMQ's OpenWire protocol exposes certain system details as plain text
CVE-2019-9735 unknown FIX slesdebian debian 4y ago An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security…
CVE-2019-10876 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated us…