Search

Found 18,360 results in 3333ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-31584 unknown FIX debian debian 2y ago Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
CVE-2024-32473 unknown FIX debian debian sles 2y ago Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on netwo…
CVE-2024-27306 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have alway…
CVE-2024-3864 low 2.5 FIX rhel rockydebian debian 2y ago Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited…
CVE-2024-3861 low 2.5 FIX rhel rockydebian debian 2y ago If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 11…
CVE-2024-3859 low 2.5 FIX rhel rockydebian debian 2y ago On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox E…
CVE-2024-3857 low 2.5 FIX rhel rockydebian debian 2y ago The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, …
CVE-2024-3854 low 2.5 FIX rhel rockydebian debian 2y ago In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 11…
CVE-2024-3852 low 2.5 FIX rhel rockydebian debian 2y ago GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVE-2024-3302 low 2.5 FIX rhel rockydebian debian 2y ago There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firef…
CVE-2024-2609 low 2.5 FIX rhel rockydebian debian 2y ago The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR …
CVE-2024-31583 unknown FIX debian debian 2y ago Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
CVE-2024-31580 unknown FIX debian debian 2y ago PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (…
CVE-2024-22262 unknown debian debian 2y ago Spring Framework URL Parsing with Host Validation
CVE-2024-29903 unknown FIX debian debian sles 2y ago Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause denial of service of the machine running Cosign the…
CVE-2024-29902 unknown FIX debian debian sles 2y ago Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cause denial of service of the host machine running C…
CVE-2024-3566 critical 9.8 9.8 FIX debian debian haskellnodejsphp 2y ago A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
CVE-2021-22573 unknown FIX debian debian 2y ago google-oauth-java-client improperly verifies cryptographic signature
CVE-2024-30261 unknown FIX slesdebian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been…
CVE-2024-30260 unknown FIX slesdebian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnera…
CVE-2024-30166 critical 9.1 9.1 FIX debian debian trustedfirmware 2y ago In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 serv…
CVE-2024-28085 low 3.3 3.3 FIX slesdebian debian kernel 2y ago wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from …
CVE-2024-29025 unknown FIX slesdebian debian 2y ago Netty's HttpPostRequestDecoder can OOM
CVE-2024-29944 critical 9.5 FIX rhel rockydebian debian 2y ago An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, …
CVE-2024-2616 critical 9.5 FIX rhel rockydebian debian 2y ago RHSA-2024:1484: firefox security update (Critical)
CVE-2023-5685 unknown debian debian 2y ago XNIO denial of service vulnerability
CVE-2024-29133 unknown FIX debian debian sles 2y ago Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
CVE-2024-29131 unknown FIX debian debian sles 2y ago Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
CVE-2024-29018 unknown FIX debian debian sles 2y ago Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows …
CVE-2024-22259 unknown debian debian 2y ago Spring Framework URL Parsing with Host Validation Vulnerability
CVE-2024-27351 unknown FIX slesdebian debian 2y ago In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a poten…
CVE-2024-23944 unknown FIX debian debian 2y ago Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
CVE-2024-27304 critical 9.8 9.8 FIX debian debian jackc 2y ago pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message si…
CVE-2024-27308 unknown FIX debian debian 2y ago Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to named pipes that have already been deregistered from…
CVE-2024-22871 unknown FIX debian debian 2y ago Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
CVE-2023-51775 unknown FIX slesdebian debian 2y ago jose4j denial of service via specifically crafted JWE
CVE-2024-21742 unknown FIX debian debian 2y ago Apache James MIME4J improper input validation vulnerability
CVE-2024-22201 unknown FIX slesdebian debian 2y ago Connection leaking on idle timeout when TCP congested
CVE-2024-22243 unknown debian debian 2y ago Spring Web vulnerable to Open Redirect or Server Side Request Forgery
CVE-2024-1635 unknown FIX debian debian 2y ago Undertow Uncontrolled Resource Consumption Vulnerability
CVE-2024-26308 unknown FIX slesdebian debian 2y ago Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
CVE-2024-25710 unknown FIX slesdebian debian 2y ago Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
CVE-2024-20925 unknown FIX slesdebian debian 2y ago Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project
CVE-2024-24758 unknown FIX slesdebian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue ha…
CVE-2024-24750 unknown FIX debian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory lea…
CVE-2024-1459 unknown FIX debian debian 2y ago Undertow Path Traversal vulnerability
CVE-2024-24762 unknown FIX slesdebian debian 2y ago `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attack…
CVE-2024-23833 unknown FIX debian debian 2y ago OpenRefine JDBC Attack Vulnerability
CVE-2023-43770 unknown 1.5 KEVFIX debian debian 2y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
CVE-2024-21490 unknown FIX debian debian sles 2y ago angular vulnerable to super-linear runtime due to backtracking
CVE-2023-50386 unknown 1.0 EXPFIX debian debian 2y ago Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
CVE-2023-50298 unknown FIX debian debian 2y ago Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
CVE-2023-50292 unknown FIX debian debian 2y ago Apache Solr Schema Designer blindly "trusts" all configsets
CVE-2023-50291 unknown FIX debian debian 2y ago Apache Solr can leak certain passwords due to System Property redaction logic inconsistencies
CVE-2024-25817 unknown FIX debian debian 2y ago Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.
CVE-2024-24821 unknown FIX debian debian sles 2y ago Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the e…
CVE-2024-24680 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with ve…
CVE-2023-4762 unknown 1.5 KEVFIX debian debian 2y ago Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2024-23635 unknown debian debian 2y ago Malicious input can provoke XSS when preserving comments
CVE-2024-24557 unknown FIX debian debian sles 2y ago Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to…
CVE-2018-12608 unknown FIX debian debian 2y ago An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows sy…
CVE-2020-27534 unknown FIX debian debian sles 2y ago util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.T…
CVE-2020-15136 unknown FIX slesdebian debian 2y ago In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on e…
CVE-2020-15114 unknown FIX slesdebian debian 2y ago In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoin…
CVE-2020-15113 unknown FIX slesdebian debian 2y ago In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS con…
CVE-2024-23334 unknown 1.0 EXPFIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static f…
CVE-2024-23829 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must tr…
CVE-2024-22233 unknown FIX debian debian 2y ago Spring Framework server Web DoS Vulnerability
CVE-2017-20189 unknown FIX debian debian 2y ago Clojure classes can be used to craft a serialized object that runs arbitrary code on deserialization
CVE-2024-22421 unknown FIX debian debian 2y ago JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Au…
CVE-2024-22420 unknown FIX debian debian 2y ago JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicio…
CVE-2024-21733 unknown FIX slesdebian debian 2y ago Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL vers…
CVE-2024-0519 unknown 1.5 KEVFIX debian debian 2y ago Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-50290 unknown FIX debian debian 2y ago Apache Solr allows read access to host environmet variables
CVE-2023-46749 unknown FIX debian debian 2y ago Apache Shiro vulnerable to path traversal
CVE-2023-49569 unknown FIX debian debian 2y ago A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, rem…
CVE-2022-3328 unknown FIX debian debian 2y ago Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVE-2023-51441 unknown debian debian sles 2y ago Apache Axis Improper Input Validation vulnerability
CVE-2023-7101 unknown 2.5 KEVEXPFIX slesdebian debian 3y ago Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Num…
CVE-2023-7024 unknown 1.5 KEVFIX debian debian 3y ago Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-51074 unknown FIX debian debian 3y ago json-path Out-of-bounds Write vulnerability
CVE-2023-49568 unknown FIX debian debian 3y ago A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted res…
CVE-2024-2408 low 2.5 FIX rocky slesdebian debian 3y ago RHSA-2023:7877: openssl security update (Low)
CVE-2023-46750 unknown debian debian 3y ago Open redirect in Apache Shiro
CVE-2019-3826 unknown FIX debian debian 3y ago A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prome…
CVE-2023-6481 unknown FIX debian debian 3y ago Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
CVE-2023-49735 unknown debian debian 3y ago Apache Tiles: Unvalidated input may lead to path traversal and XXE
CVE-2023-6345 unknown 1.5 KEVFIX debian debian 3y ago Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chr…
CVE-2023-6378 unknown FIX debian debian 3y ago logback serialization vulnerability
CVE-2022-41678 unknown FIX debian debian 3y ago Apache ActiveMQ Deserialization of Untrusted Data vulnerability
CVE-2023-34053 unknown FIX debian debian 3y ago Spring Framework vulnerable to denial of service
CVE-2023-49081 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create…
CVE-2023-49082 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even cre…
CVE-2023-33202 unknown FIX debian debian 3y ago Bouncy Castle Denial of Service (DoS)
CVE-2022-46337 unknown FIX debian debian 3y ago Apache Derby: LDAP injection vulnerability in authenticator
CVE-2023-5072 unknown FIX debian debian 3y ago Java: DoS Vulnerability in JSON-JAVA
CVE-2023-47627 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parse…
CVE-2023-47641 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vulnerability regarding the inconsistent interpretation of the http protoc…
CVE-2023-47122 unknown FIX debian debian 3y ago Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the loc…
CVE-2023-46735 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` return…