Search

Found 16,968 results in 1123ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-26520 unknown FIX slesdebian debian 4y ago Path traversal in org.postgresql:postgresql
CVE-2022-26652 unknown FIX debian debian 4y ago NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
CVE-2021-3654 unknown FIX slesdebian debian 4y ago A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
CVE-2019-16928 critical 10.0 KEVFIX arch archdebian debian 4y ago Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CVE-2015-4902 unknown 1.5 KEVFIX debian debian 4y ago Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
CVE-2015-2590 unknown 1.5 KEVFIX debian debian 4y ago An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
CVE-2022-24329 unknown FIX debian debian 4y ago Improper Locking in JetBrains Kotlin
CVE-2022-24614 unknown debian debian 4y ago Allocation of Resources Without Limits or Throttling in metadata-extractor
CVE-2022-24613 unknown debian debian 4y ago Improper Handling of Exceptional Conditions inn metadata-extractor
CVE-2022-24615 unknown FIX debian debian 4y ago Uncaught Exception in zip4j
CVE-2022-0609 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-23649 unknown FIX debian debian sles 4y ago Cosign provides container signing, verification, and storage in an OCI registry for the sigstore project. Prior to version 1.5.2, Cosign can be manipulated to claim that an entry for a signature exis…
CVE-2022-23134 unknown 1.5 KEVFIX slesdebian debian 4y ago Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
CVE-2022-23131 unknown 1.5 KEVFIX slesdebian debian 4y ago Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
CVE-2020-28466 unknown FIX debian debian 4y ago This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer fro…
CVE-2020-13401 unknown FIX slesdebian debian 4y ago An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts…
CVE-2018-1099 unknown FIX slesdebian debian 4y ago DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other add…
CVE-2018-1098 unknown FIX slesdebian debian 4y ago A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done wit…
CVE-2019-3902 unknown FIX slesdebian debian 4y ago A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
CVE-2021-3127 unknown FIX debian debian 4y ago NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
CVE-2021-3907 unknown FIX debian debian 4y ago OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to…
CVE-2020-27955 unknown 1.0 EXPFIX debian debian 4y ago Git LFS 2.12.0 allows Remote Code Execution.
CVE-2020-15157 unknown FIX debian debian sles 4y ago In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Sche…
CVE-2019-14900 unknown FIX slesdebian debian 4y ago SQL Injection in Hibernate ORM
CVE-2021-31684 unknown FIX debian debian 4y ago Out of bounds read in json-smart
CVE-2022-23614 unknown FIX debian debian 4y ago Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In…
CVE-2020-13957 unknown FIX debian debian 4y ago Incorrect Authorization in Apache Solr
CVE-2018-11802 unknown FIX debian debian 4y ago Incorrect Authorization in Apache Solr
CVE-2020-7778 unknown FIX debian debian 4y ago This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
CVE-2020-13943 unknown FIX slesdebian debian 4y ago If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation o…
CVE-2020-25638 unknown FIX slesdebian debian 4y ago SQL injection in hibernate-core
CVE-2020-13920 unknown FIX debian debian 4y ago Improper Authentication in Apache ActiveMQ
CVE-2020-11998 unknown FIX debian debian 4y ago Remote code execution in Apache ActiveMQ
CVE-2020-17523 unknown FIX debian debian 4y ago Authentication bypass in Apache Shiro
CVE-2020-13947 unknown FIX debian debian 4y ago Cross-site scripting (XSS) in Apache ActiveMQ
CVE-2020-27782 unknown FIX debian debian 4y ago Denial of service in Undertow
CVE-2019-17566 unknown FIX debian debian sles 4y ago Server-side request forgery (SSRF) in Apache Batik
CVE-2022-24450 unknown FIX debian debian 4y ago NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
CVE-2021-41496 unknown slesdebian debian 4y ago Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative val…
CVE-2021-41495 unknown slesdebian debian 4y ago Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attack…
CVE-2022-21724 unknown FIX slesdebian debian 4y ago pgjdbc Does Not Check Class Instantiation when providing Plugin Classes
CVE-2021-43859 unknown FIX slesdebian debian 4y ago Denial of Service by injecting highly recursive collections or maps in XStream
CVE-2022-23601 unknown FIX debian debian 4y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in t…
CVE-2022-23181 unknown FIX slesdebian debian 4y ago The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed…
CVE-2022-23607 unknown FIX debian debian 4y ago treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as …
CVE-2021-44142 critical 9.5 FIX arch arch sles rocky 4y ago RHSA-2022:0332: samba security and bug fix update (Critical)
CVE-2014-7169 unknown 2.5 KEVEXPFIX debian debian 4y ago GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vul…
CVE-2014-6271 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
CVE-2021-23566 unknown FIX debian debian 4y ago The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
CVE-2022-23221 unknown FIX debian debian 4y ago Arbitrary code execution in H2 Console
CVE-2022-23305 critical 9.8 9.8 FIX debian debian sles rocky apachenetappbroadcom 4y ago RHSA-2022:0290: parfait:0.5 security update (Important)
CVE-2021-22060 unknown debian debian 5y ago Log entry injection in Spring Framework
CVE-2020-6572 unknown 1.5 KEVFIX debian debian 5y ago Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2019-10149 critical 10.0 KEVEXPFIX arch archdebian debian 5y ago A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2021-23382 unknown FIX debian debian 5y ago The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused …
CVE-2021-33430 unknown FIX slesdebian debian 5y ago A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large dimensions (over 32) from Python code, which could let a mali…
CVE-2021-22569 unknown FIX slesdebian debian 5y ago A potential Denial of Service issue in protobuf-java
CVE-2021-42392 unknown FIX debian debian 5y ago RCE in H2 Console
CVE-2022-21653 unknown FIX debian debian 5y ago Hash collision in typelevel jawn
CVE-2021-44548 unknown FIX debian debian 5y ago Apache Solr Improper Input Validation and Path Traversal
CVE-2020-13936 unknown FIX slesdebian debian 5y ago Sandbox Bypass in Apache Velocity Engine
CVE-2021-45943 unknown FIX debian debian 5y ago GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment…
CVE-2021-44732 critical 9.8 9.8 FIX debian debian armtrustedfirmware 5y ago Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
CVE-2021-34141 unknown slesdebian debian 5y ago An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor sta…
CVE-2021-23463 unknown FIX debian debian 5y ago Improper Restriction of XML External Entity Reference in com.h2database:h2.
CVE-2021-43113 unknown FIX debian debian 5y ago Command injection in itext7-core
CVE-2021-4102 critical 10.0 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-45046 unknown 2.5 KEVEXPFIX debian debian sles 5y ago Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in…
CVE-2020-25717 critical 9.5 FIX arch arch sles rocky 5y ago RHSA-2022:0332: samba security and bug fix update (Critical)
CVE-2021-44228 critical 10.0 KEVEXPFIX arch archdebian debian sles 5y ago Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
CVE-2020-28491 unknown FIX slesdebian debian 5y ago Denial of Service (DoS) in Jackson Dataformat CBOR
CVE-2020-36189 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36187 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36188 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36184 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36180 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36181 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36185 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36179 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36182 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-24750 unknown FIX slesdebian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-35491 unknown FIX debian debian 5y ago Serialization gadgets exploit in jackson-databind
CVE-2020-35490 unknown FIX debian debian 5y ago Serialization gadgets exploit in jackson-databind
CVE-2020-24616 unknown FIX debian debian 5y ago Code Injection in jackson-databind
CVE-2021-43527 critical 9.5 FIX arch arch sles rocky 5y ago NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatu…
CVE-2021-41270 unknown FIX debian debian 5y ago Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 bef…
CVE-2021-41268 unknown FIX debian debian 5y ago Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version…
CVE-2021-41267 unknown FIX debian debian 5y ago Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers"…
CVE-2020-36186 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2021-45710 unknown FIX slesdebian debian 5y ago An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory…
CVE-2021-3909 unknown FIX debian debian 5y ago OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests…
CVE-2021-41973 unknown FIX debian debian 5y ago Infinite loop in Apache MINA
CVE-2021-42013 critical 10.0 KEVEXPFIX arch archdebian debian 5y ago It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Al…
CVE-2021-30551 critical 10.0 KEVFIX arch archdebian debian sles 5y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-21148 critical 10.0 KEVFIX arch archdebian debian sles 5y ago Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2020-6820 critical 10.0 KEVFIX arch arch slesdebian debian 5y ago Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unsp…
CVE-2020-6819 critical 10.0 KEVFIX arch arch slesdebian debian 5y ago Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, caus…
CVE-2020-16010 unknown 1.5 KEVFIX debian debian 5y ago Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a craft…
CVE-2020-0041 unknown 1.5 KEVFIX debian debian 5y ago Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was ob…
CVE-2019-2215 unknown 2.5 KEVEXPFIX debian debian 5y ago Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-…