Search

Found 18,413 results in 3319ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-34624 unknown FIX debian debian 3y ago htmlcleaner vulnerable to stack exhaustion
CVE-2023-3079 unknown 1.5 KEVFIX debian debian 3y ago Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-33546 unknown FIX slesdebian debian 3y ago janino vulnerable to denial of service due to stack overflow
CVE-2023-1521 unknown FIX slesdebian debian 3y ago On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (…
CVE-2023-33199 unknown FIX slesdebian debian 3y ago Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed proposed entry of the `intoto/v0.0.2` type can cause a pan…
CVE-2023-32697 unknown FIX debian debian 3y ago Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
CVE-2023-32409 unknown 1.5 KEVFIX debian debian 3y ago Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impa…
CVE-2023-29159 unknown FIX debian debian 3y ago Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
CVE-2023-53160 unknown FIX slesdebian debian 3y ago The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
CVE-2023-32082 unknown FIX debian debian sles 3y ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease wh…
CVE-2016-3427 unknown 1.5 KEVFIX slesdebian debian 3y ago Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions …
CVE-2014-0196 unknown 2.5 KEVEXPFIX debian debian 3y ago Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with l…
CVE-2023-31141 unknown debian debian 3y ago OpenSearch issue with fine-grained access control during extremely rare race conditions
CVE-2022-43552 low 2.5 FIX rheldebian debian sles 3y ago A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operat…
CVE-2022-36227 low 2.5 FIX rocky rhel sles 3y ago RHSA-2023:3018: libarchive security update (Low)
CVE-2022-35252 low 2.5 FIX rheldebian debian sles 3y ago When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. …
CVE-2022-28805 low 2.5 FIX rhel slesdebian debian 3y ago Low: lua security update
CVE-2022-1615 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:2987: samba security, bug fix, and enhancement update (Low)
CVE-2023-30551 unknown FIX slesdebian debian 3y ago Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory witho…
CVE-2023-22665 unknown FIX debian debian 3y ago Arbitrary javascript injection in Apache Jena
CVE-2023-2136 unknown 1.5 KEVFIX debian debian 3y ago Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (…
CVE-2023-1892 unknown FIX debian debian 3y ago Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVE-2023-29197 unknown FIX debian debian 3y ago guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names a…
CVE-2023-26048 unknown FIX slesdebian debian 3y ago OutOfMemoryError for large multipart without filename in Eclipse Jetty
CVE-2023-21968 low 3.7 3.7 FIX rhel rocky sles oraclenetapp 3y ago RHSA-2023:4103: java-1.8.0-ibm security update (Important)
CVE-2023-26049 unknown FIX slesdebian debian 3y ago Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
CVE-2023-2033 unknown 1.5 KEVFIX debian debian 3y ago Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-20863 unknown debian debian 3y ago Spring Framework vulnerable to denial of service
CVE-2022-41862 low 2.5 FIX rhel rocky sles 3y ago RHSA-2023:7016: libpq security update (Low)
CVE-2023-28840 unknown FIX debian debian sles 3y ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon componen…
CVE-2023-28841 unknown FIX debian debian sles 3y ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon componen…
CVE-2023-28842 unknown FIX debian debian sles 3y ago Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon compone…
CVE-2021-28235 unknown FIX slesdebian debian 3y ago Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CVE-2022-3038 unknown 1.5 KEVFIX debian debian 3y ago Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2023-20860 unknown debian debian 3y ago Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
CVE-2023-28628 unknown debian debian 3y ago lambdaisland/uri `authority-regex` returns the wrong authority
CVE-2023-20861 unknown debian debian 3y ago Spring Framework vulnerable to denial of service via specially crafted SpEL expression
CVE-2023-1370 unknown FIX debian debian 3y ago json-smart Uncontrolled Recursion vulnerability
CVE-2023-1436 unknown FIX slesdebian debian 3y ago Jettison vulnerable to infinite recursion
CVE-2021-46877 unknown FIX slesdebian debian 3y ago jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonN…
CVE-2023-28531 critical 9.8 9.8 FIX debian debian openbsd 3y ago ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
CVE-2023-24535 unknown FIX debian debian 3y ago Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a…
CVE-2023-26464 unknown FIX debian debian 3y ago Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
CVE-2023-27476 unknown FIX slesdebian debian 3y ago OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lx…
CVE-2022-41918 unknown FIX debian debian 3y ago OpenSearch has issue with fine-grained access control of indices backing data streams
CVE-2022-3277 unknown FIX slesdebian debian 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2022-4492 unknown FIX debian debian 3y ago Undertow client not checking server identity presented by server certificate in https connections
CVE-2023-26302 unknown FIX slesdebian debian 3y ago Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.
CVE-2023-26303 unknown FIX slesdebian debian 3y ago Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.
CVE-2022-46169 unknown 2.5 KEVEXPFIX debian debian sles 3y ago Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
CVE-2023-30798 unknown FIX debian debian 3y ago There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause e…
CVE-2022-24894 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers…
CVE-2022-24895 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the…
CVE-2022-47951 unknown FIX debian debian sles 3y ago An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0…
CVE-2023-23613 unknown debian debian 3y ago Field-level security issue with .keyword fields in OpenSearch
CVE-2023-23612 unknown debian debian 3y ago Issue with whitespace in JWT roles in OpenSearch
CVE-2023-22742 unknown FIX slesdebian debian 3y ago libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versio…
CVE-2022-47950 unknown FIX slesdebian debian 3y ago An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file c…
CVE-2022-25901 unknown FIX debian debian 3y ago cookiejar Regular Expression Denial of Service via Cookie.parse function
CVE-2023-22602 unknown debian debian 3y ago Apache Shiro Interpretation Conflict vulnerability
CVE-2022-41721 unknown FIX debian debian 3y ago A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from th…
CVE-2022-46176 unknown FIX debian debian sles 3y ago Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could explo…
CVE-2023-22899 unknown FIX debian debian 3y ago Zip4j Origin Validation Error
CVE-2023-22466 unknown FIX debian debian 4y ago Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` …
CVE-2022-45143 unknown FIX slesdebian debian 4y ago The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from use…
CVE-2022-40151 unknown slesdebian debian 4y ago XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow
CVE-2022-41966 unknown FIX slesdebian debian 4y ago XStream can cause Denial of Service via stack overflow
CVE-2022-46393 critical 9.8 9.8 FIX slesdebian debianfedora fedora armtrustedfirmware 4y ago An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is en…
CVE-2022-45693 unknown FIX slesdebian debian 4y ago Jettison Out-of-bounds Write vulnerability
CVE-2022-45685 unknown FIX slesdebian debian 4y ago Jettison Out-of-bounds Write vulnerability
CVE-2022-41915 unknown FIX slesdebian debian 4y ago Netty vulnerable to HTTP Response splitting from assigning header value iterator
CVE-2022-41881 unknown FIX slesdebian debian 4y ago HAProxyMessageDecoder Stack Exhaustion DoS
CVE-2022-3510 unknown FIX slesdebian debian 4y ago Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVE-2022-3509 unknown FIX slesdebian debian 4y ago Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVE-2022-23491 unknown FIX slesdebian debian 4y ago Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates fro…
CVE-2022-44900 unknown FIX debian debian 4y ago A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z fil…
CVE-2022-4262 unknown 1.5 KEVFIX debian debian 4y ago Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2021-37533 unknown FIX slesdebian debian 4y ago Apache Commons Net vulnerable to information leakage via malicious server
CVE-2022-46146 unknown FIX slesdebian debian 4y ago Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypa…
CVE-2022-46149 unknown FIX debian debian sles 4y ago Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementatio…
CVE-2022-45907 unknown FIX debian debian 4y ago In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CVE-2022-4135 unknown 1.5 KEVFIX debian debian 4y ago Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page…
CVE-2022-4065 unknown FIX slesdebian debian 4y ago TestNG is vulnerable to Path Traversal
CVE-2022-45047 critical 9.8 9.8 FIX debian debian apache 4y ago Unsafe deserialization in Apache MINA SSHD
CVE-2022-2990 low 2.5 FIX rhel rocky sles 4y ago RHSA-2022:7822: container-tools:rhel8 security, bug fix, and enhancement update (Low)
CVE-2022-24736 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-24735 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-23645 low 2.5 FIX rhel rockydebian debian 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-2211 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-1122 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7645: openjpeg2 security update (Low)
CVE-2022-0897 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2021-46195 low 2.5 FIX rheldebian debian sles 4y ago Low: mingw-gcc security and bug fix update
CVE-2021-44269 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7558: wavpack security update (Low)
CVE-2021-3507 low 2.5 FIX rhel sles rocky 4y ago A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers fr…
CVE-2020-23903 low 2.5 FIX rhelarch arch sles 4y ago Low: speex security update
CVE-2022-45136 unknown FIX debian debian 4y ago Apache Jena vulnerable to Deserialization of Untrusted Data
CVE-2022-41854 unknown FIX slesdebian debian 4y ago Snakeyaml vulnerable to Stack overflow leading to denial of service
CVE-2022-42964 unknown FIX debian debian 4y ago An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method
CVE-2022-42252 unknown FIX slesdebian debian 4y ago If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default f…
CVE-2022-3723 unknown 1.5 KEVFIX debian debian 4y ago Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)