Search

Found 15,740 results in 2144ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-30973 unknown FIX slesdebian debian 4y ago Regular expression denial of service in apache tika
CVE-2022-29248 unknown FIX arch archdebian debian 4y ago Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the …
CVE-2021-3629 unknown FIX debian debian 4y ago Undertow Uncontrolled Resource Consumption
CVE-2021-3597 unknown FIX debian debian 4y ago undertow Race Condition vulnerability
CVE-2015-4495 unknown 2.5 KEVEXPFIX debian debian 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2014-3153 unknown 2.5 KEVEXPFIX debian debian 4y ago The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
CVE-2021-20328 unknown FIX debian debian 4y ago Improper Certificate Validation in MongoDB
CVE-2019-17560 unknown FIX debian debian 4y ago Improper Certificate Validation in Apache Netbeans
CVE-2013-5123 unknown 1.0 EXPFIX slesdebian debian 4y ago The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVE-2019-12401 unknown FIX debian debian 4y ago Apache Solr vulnerable to XML Bomb
CVE-2022-29173 unknown FIX debian debian 4y ago go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, …
CVE-2021-22096 unknown debian debian 4y ago Improper Output Neutralization for Logs in Spring Framework
CVE-2021-40797 unknown FIX slesdebian debian 4y ago An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authentic…
CVE-2021-40085 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
CVE-2021-38598 unknown FIX slesdebian debian 4y ago OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending c…
CVE-2021-38155 unknown FIX slesdebian debian 4y ago OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). …
CVE-2021-20267 unknown FIX slesdebian debian 4y ago A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersona…
CVE-2021-22118 unknown FIX debian debian 4y ago Improper Privilege Management in Spring Framework
CVE-2021-33194 unknown FIX slesdebian debian 4y ago golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
CVE-2020-29582 unknown FIX debian debian 4y ago Incorrect Default Permissions in JetBrains Kotlin
CVE-2020-22083 low 2.5 arch archdebian debian 4y ago ** DISPUTED ** jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and cl…
CVE-2020-17376 unknown FIX slesdebian debian 4y ago An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously under…
CVE-2020-12692 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
CVE-2020-12691 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then …
CVE-2020-12689 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escala…
CVE-2020-1745 unknown FIX debian debian 4y ago Improper Authorization in Undertoe
CVE-2020-1757 unknown FIX debian debian 4y ago Improper Input Validation in Undertow
CVE-2019-17561 unknown FIX debian debian 4y ago Improper Verification of Cryptographic Signature in Apache Netbeans
CVE-2015-9543 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs …
CVE-2019-14888 unknown FIX debian debian 4y ago Undertow vulnerable to Uncontrolled Resource Consumption
CVE-2016-1000027 unknown FIX debian debian 4y ago Pivotal Spring Framework contains unsafe Java deserialization methods
CVE-2019-19687 unknown FIX debian debian 4y ago OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enfor…
CVE-2019-0205 unknown FIX slesdebian debian 4y ago Loop with Unreachable Exit Condition in Apache Thrift
CVE-2019-12415 unknown debian debian 4y ago Improper Restriction of XML External Entity Reference in Apache POI
CVE-2019-17091 unknown FIX debian debian 4y ago Cross-site Scripting in Eclipse Mojarra
CVE-2019-0231 unknown FIX debian debian 4y ago Cleartext Transmission of Sensitive Information in Apache MINA
CVE-2019-16370 unknown FIX debian debian 4y ago Use of a weak cryptographic algorithm in Gradle
CVE-2019-14433 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external excepti…
CVE-2019-14271 unknown FIX slesdebian debian 4y ago In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the conten…
CVE-2019-13509 unknown FIX slesdebian debian 4y ago In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a…
CVE-2017-11365 unknown FIX debian debian 4y ago Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The compo…
CVE-2019-11841 unknown FIX debian debian 4y ago A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 488…
CVE-2021-1048 unknown 1.5 KEVFIX slesdebian debian 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2022-24434 unknown FIX debian debian 4y ago Crash in HeaderParser in dicer
CVE-2014-9390 unknown 1.0 EXPFIX debian debian 4y ago Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; …
CVE-2014-9720 unknown FIX debian debian 4y ago Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determi…
CVE-2014-4172 unknown FIX debian debian 4y ago Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
CVE-2011-4617 low 1.2 FIX debian debian python 4y ago virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.
CVE-2012-3442 unknown FIX debian debian 4y ago The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which…
CVE-2013-4278 low 3.5 FIX debian debian openstack 4y ago The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot…
CVE-2014-1948 low 2.6 FIX debian debian openstack 4y ago OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARN…
CVE-2014-0056 low 2.1 FIX ubuntu ubuntudebian debian openstack 4y ago The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants …
CVE-2013-4463 low 2.1 FIX debian debian openstack 4y ago OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumpti…
CVE-2013-4469 low 1.9 FIX debian debian openstack 4y ago OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (ho…
CVE-2014-1624 low 3.3 FIX slesdebian debian python 4y ago Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to …
CVE-2022-30126 unknown slesdebian debian 4y ago Regular expression denial of service in apache tika
CVE-2022-25169 unknown slesdebian debian 4y ago Apache Tika vulnerable to uncontrolled memory consumption
CVE-2014-3607 unknown FIX debian debian 4y ago Improper Certificate Validation in vt-ldap
CVE-2018-11407 unknown FIX debian debian 4y ago An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by l…
CVE-2018-14371 unknown FIX debian debian 4y ago Path Traversal in Eclipse Mojarra
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2017-16790 unknown FIX debian debian 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST …
CVE-2008-5619 unknown 1.0 EXPFIX debian debian 4y ago html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attack…
CVE-2016-9606 unknown FIX debian debian 4y ago JBoss RESTEasy vulnerable to Improper Input Validation
CVE-2018-14774 unknown FIX debian debian 4y ago An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using Http…
CVE-2014-1934 low 3.3 FIX debian debiansuse suse travis_shirk 4y ago tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.
CVE-2018-1000665 unknown FIX debian debian 4y ago Improper Neutralization of Input During Web Page Generation in Dojo Dojo Objective Harness
CVE-2018-17983 unknown FIX slesdebian debian 4y ago cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.
CVE-2018-7749 unknown FIX debian debian 4y ago The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authe…
CVE-2018-1294 unknown FIX debian debian 4y ago Improper Input Validation Apache Commons Email
CVE-2018-11385 unknown FIX debian debian 4y ago An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerabil…
CVE-2017-16652 unknown FIX debian debian 4y ago An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler t…
CVE-2017-16654 unknown FIX debian debian 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the …
CVE-2018-11408 unknown FIX debian debian 4y ago The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnera…
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2018-19859 unknown FIX debian debian 4y ago OpenRefine Directory Traversal
CVE-2018-11386 unknown FIX debian debian 4y ago An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler c…
CVE-2018-11406 unknown FIX debian debian 4y ago An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session …
CVE-2017-15706 unknown FIX slesdebian debian 4y ago As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorit…
CVE-2016-6810 unknown FIX debian debian 4y ago Improper Neutralization of Input During Web Page Generation Apache ActiveMQ
CVE-2018-19790 unknown FIX debian debian 4y ago An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_f…
CVE-2018-19789 unknown FIX debian debian 4y ago An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `strin…
CVE-2017-15691 unknown FIX debian debian 4y ago Improper Restriction of XML External Entity Reference in Apache uimaj
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2017-1000190 unknown FIX debian debian 4y ago SimpleXML has XML External Entity (XXE) vulnerability
CVE-2018-1000079 unknown FIX slesdebian debian 4y ago RubyGems Path Traversal vulnerability
CVE-2018-1000078 unknown FIX slesdebian debian 4y ago RubyGems Cross-site Scripting vulnerability
CVE-2018-1000077 unknown FIX slesdebian debian 4y ago RubyGems Improper Input Validation vulnerability
CVE-2018-1000076 unknown FIX slesdebian debian 4y ago RubyGems Improper Verification of Cryptographic Signature vulnerability
CVE-2018-1000074 unknown FIX slesdebian debian 4y ago RubyGems Deserialization of Untrusted Data vulnerability
CVE-2017-1000426 unknown FIX debian debian 4y ago MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.
CVE-2018-8036 unknown FIX slesdebian debian 4y ago Loop with Unreachable Exit Condition in Apache PDFBox
CVE-2018-1297 unknown debian debian 4y ago Missing certificate validation in Apache JMeter
CVE-2018-1287 unknown debian debian 4y ago Missing certificate validation in Apache JMeter
CVE-2017-3590 low 3.3 3.3 FIX debian debian oracle 4y ago Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows…
CVE-2017-18191 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt t…
CVE-2017-16653 unknown FIX debian debian 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different token…
CVE-2017-12165 unknown FIX debian debian 4y ago Undertow Request Smuggling vulnerability
CVE-2017-12196 unknown FIX debian debian 4y ago Incorrect Authorization in Undertow
CVE-2017-7559 unknown FIX debian debian 4y ago Undertow vulnerable to Request Smuggling