Search

Found 16,808 results in 758ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-9735 unknown FIX slesdebian debian 4y ago An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security…
CVE-2019-10876 unknown FIX slesdebian debian 4y ago An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated us…
CVE-2018-14635 unknown FIX slesdebian debian 4y ago When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service cou…
CVE-2017-7543 unknown FIX slesdebian debian 4y ago A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutro…
CVE-2017-2673 unknown FIX slesdebian debian 4y ago An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and uninte…
CVE-2017-7550 critical 9.8 9.8 FIX debian debian sles rhel redhat 4y ago A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive infor…
CVE-2018-8012 unknown FIX slesdebian debian 4y ago Missing Authorization in Apache ZooKeeper
CVE-2018-8088 unknown FIX slesdebian debian 4y ago Improper Access Control in SLF4J
CVE-2018-1313 unknown FIX slesdebian debian 4y ago Improper Access Control in Apache Derby
CVE-2018-5382 unknown FIX debian debian 4y ago Improper Validation of Integrity Check Value in Bouncy Castle
CVE-2022-29885 unknown 1.0 EXPFIX slesdebian debian 4y ago The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to r…
CVE-2022-22971 unknown debian debian 4y ago Allocation of Resources Without Limits or Throttling in Spring Framework
CVE-2022-22970 unknown debian debian 4y ago Denial of service in Spring Framework
CVE-2018-1000075 unknown FIX slesdebian debian 4y ago RubyGems Infinite Loop vulnerability
CVE-2018-1000073 unknown FIX slesdebian debian 4y ago RubyGems Link Following vulnerability
CVE-2021-23792 unknown FIX debian debian 4y ago External Entity Reference in TwelveMonkeys ImageIO
CVE-2022-28890 unknown FIX debian debian 4y ago XML External Entity Reference in apache jena
CVE-2013-6430 unknown FIX debian debian 4y ago Improper Neutralization of Input During Web Page Generation in Spring Framework
CVE-2013-2255 unknown FIX debian debian 4y ago HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
CVE-2014-0160 unknown 2.5 KEVEXPFIX debian debian 4y ago The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
CVE-2009-3695 unknown FIX debian debian 4y ago Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) Emai…
CVE-2009-2659 unknown FIX debian debian 4y ago The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory trav…
CVE-2009-1275 unknown FIX debian debian 4y ago Apache Tiles Vulnerable to XSS via EL Expression Injection
CVE-2009-0217 unknown FIX debian debian 4y ago Apache XML Security For Java vulnerable to authentication bypass by HMAC truncation
CVE-2008-3909 unknown FIX debian debian 4y ago The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to con…
CVE-2008-2942 unknown FIX debian debian 4y ago Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
CVE-2008-2302 unknown FIX debian debian 4y ago Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject…
CVE-2007-6721 unknown FIX debian debian 4y ago Legion of the Bouncy Castle Java Cryptography API Bleichenbacher Oracle Vulnerability
CVE-2007-6382 unknown FIX debian debian 4y ago The Event Dispatch Thread in Robocode before 1.5.1 allows remote attackers to execute arbitrary Java code by using a robot to invoke the SwingUtilities.invokeLater method.
CVE-2007-5712 unknown FIX debian debian 4y ago The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows re…
CVE-2007-5201 unknown FIX debian debian 4y ago The FTP backend for Duplicity before 0.4.9 sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the process and its argument…
CVE-2007-2353 unknown 1.0 EXP debian debian 4y ago Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
CVE-2007-0405 unknown FIX debian debian 4y ago The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different…
CVE-2007-0404 unknown FIX debian debian 4y ago bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shel…
CVE-2006-7217 unknown FIX debian debian 4y ago Apache Derby SQL Injection
CVE-2005-4849 unknown FIX debian debian 4y ago Apache Derby exposes user and password attributes
CVE-2021-41945 critical 9.5 FIX arch archdebian debian 4y ago Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
CVE-2022-24891 unknown FIX debian debian 4y ago Cross-site Scripting in org.owasp.esapi:esapi
CVE-2022-23457 unknown FIX debian debian 4y ago Path traversal in the OWASP Enterprise Security API
CVE-2022-29577 unknown FIX debian debian 4y ago Cross-site Scripting in OWASP AntiSamy
CVE-2022-28367 unknown FIX debian debian 4y ago Cross-site Scripting in OWASP AntiSamy
CVE-2022-28366 unknown FIX slesdebian debian 4y ago Denial of service in HtmlUnit-Neko
CVE-2022-24828 unknown FIX debian debian sles 4y ago Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control …
CVE-2011-4076 unknown FIX debian debian 4y ago OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http o…
CVE-2011-3147 unknown FIX debian debian 4y ago Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
CVE-2010-4237 unknown FIX debian debian 4y ago Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-midd…
CVE-2022-22968 unknown debian debian 4y ago Improper handling of case sensitivity in Spring Framework
CVE-2022-1364 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2018-16886 unknown FIX slesdebian debian 4y ago etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd …
CVE-2022-24839 unknown FIX slesdebian debian 4y ago org.nokogiri:nekohtml vulnerable to Uncontrolled Resource Consumption
CVE-2022-23437 unknown FIX slesdebian debian 4y ago Infinite Loop in Apache Xerces Java
CVE-2021-22600 unknown 1.5 KEVFIX slesdebian debian 4y ago Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly fo…
CVE-2022-22950 unknown debian debian 4y ago Allocation of Resources Without Limits or Throttling in Spring Framework
CVE-2022-22965 unknown 2.5 KEVEXP debian debian 4y ago Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-0543 unknown 2.5 KEVEXPFIX debian debian 4y ago Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CVE-2019-18887 unknown FIX debian debian 4y ago An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/h…
CVE-2017-9841 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by …
CVE-2020-7247 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
CVE-2010-4345 unknown 2.5 KEVEXPFIX debian debian 4y ago Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary comm…
CVE-2010-4344 unknown 2.5 KEVEXPFIX debian debian 4y ago Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conj…
CVE-2009-1151 unknown 2.5 KEVEXPFIX debian debian 4y ago Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
CVE-2022-24775 unknown FIX debian debian 4y ago guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values…
CVE-2020-14326 unknown FIX debian debian 4y ago RESTEasy 4.5.5.Final in hash flooding
CVE-2021-29607 critical 9.5 FIX arch archdebian debian 4y ago TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) a…
CVE-2022-26520 unknown FIX slesdebian debian 4y ago Path traversal in org.postgresql:postgresql
CVE-2022-26652 unknown FIX debian debian 4y ago NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
CVE-2021-3654 unknown FIX slesdebian debian 4y ago A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
CVE-2019-16928 critical 10.0 KEVFIX arch archdebian debian 4y ago Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CVE-2015-4902 unknown 1.5 KEVFIX debian debian 4y ago Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
CVE-2015-2590 unknown 1.5 KEVFIX debian debian 4y ago An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
CVE-2022-24329 unknown FIX debian debian 4y ago Improper Locking in JetBrains Kotlin
CVE-2022-24614 unknown debian debian 4y ago Allocation of Resources Without Limits or Throttling in metadata-extractor
CVE-2022-24613 unknown debian debian 4y ago Improper Handling of Exceptional Conditions inn metadata-extractor
CVE-2022-24615 unknown FIX debian debian 4y ago Uncaught Exception in zip4j
CVE-2022-0609 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-23649 unknown FIX debian debian sles 4y ago Cosign provides container signing, verification, and storage in an OCI registry for the sigstore project. Prior to version 1.5.2, Cosign can be manipulated to claim that an entry for a signature exis…
CVE-2022-23134 unknown 1.5 KEVFIX slesdebian debian 4y ago Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
CVE-2022-23131 unknown 1.5 KEVFIX slesdebian debian 4y ago Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
CVE-2020-28466 unknown FIX debian debian 4y ago This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer fro…
CVE-2020-13401 unknown FIX slesdebian debian 4y ago An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts…
CVE-2018-1099 unknown FIX slesdebian debian 4y ago DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other add…
CVE-2018-1098 unknown FIX slesdebian debian 4y ago A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done wit…
CVE-2019-3902 unknown FIX slesdebian debian 4y ago A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
CVE-2021-3127 unknown FIX debian debian 4y ago NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
CVE-2021-3907 unknown FIX debian debian 4y ago OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to…
CVE-2020-27955 unknown 1.0 EXPFIX debian debian 4y ago Git LFS 2.12.0 allows Remote Code Execution.
CVE-2020-15157 unknown FIX debian debian sles 4y ago In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Sche…
CVE-2019-14900 unknown FIX slesdebian debian 4y ago SQL Injection in Hibernate ORM
CVE-2021-31684 unknown FIX debian debian 4y ago Out of bounds read in json-smart
CVE-2022-23614 unknown FIX debian debian 4y ago Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In…
CVE-2020-13957 unknown FIX debian debian 4y ago Incorrect Authorization in Apache Solr
CVE-2018-11802 unknown FIX debian debian 4y ago Incorrect Authorization in Apache Solr
CVE-2020-7778 unknown FIX debian debian 4y ago This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
CVE-2020-13943 unknown FIX slesdebian debian 4y ago If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation o…
CVE-2020-25638 unknown FIX slesdebian debian 4y ago SQL injection in hibernate-core
CVE-2020-13920 unknown FIX debian debian 4y ago Improper Authentication in Apache ActiveMQ
CVE-2020-11998 unknown FIX debian debian 4y ago Remote code execution in Apache ActiveMQ
CVE-2020-17523 unknown FIX debian debian 4y ago Authentication bypass in Apache Shiro
CVE-2020-13947 unknown FIX debian debian 4y ago Cross-site scripting (XSS) in Apache ActiveMQ
CVE-2020-27782 unknown FIX debian debian 4y ago Denial of service in Undertow