Search

Found 15,800 results in 726ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-36187 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36188 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36184 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36180 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36181 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36185 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36179 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-36182 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-24750 unknown FIX slesdebian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2020-35491 unknown FIX debian debian 5y ago Serialization gadgets exploit in jackson-databind
CVE-2020-35490 unknown FIX debian debian 5y ago Serialization gadgets exploit in jackson-databind
CVE-2020-24616 unknown FIX debian debian 5y ago Code Injection in jackson-databind
CVE-2021-41270 unknown FIX debian debian 5y ago Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 bef…
CVE-2021-41268 unknown FIX debian debian 5y ago Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version…
CVE-2021-41267 unknown FIX debian debian 5y ago Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers"…
CVE-2020-36186 unknown FIX debian debian 5y ago Unsafe Deserialization in jackson-databind
CVE-2021-45710 unknown FIX slesdebian debian 5y ago An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory…
CVE-2021-3572 low 2.5 FIX arch arch sles rocky 5y ago A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest…
CVE-2021-3909 unknown FIX debian debian 5y ago OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests…
CVE-2020-24370 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4510: lua security update (Low)
CVE-2021-20266 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4489: rpm security, bug fix, and enhancement update (Low)
CVE-2021-3200 low 2.5 FIX sles rockydebian debian 5y ago Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c…
CVE-2020-16135 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4387: libssh security update (Low)
CVE-2018-20673 low 2.5 debian debian sles rocky 5y ago RHSA-2021:4386: gcc security and bug fix update (Low)
CVE-2020-14155 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2019-20838 low 2.5 sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2020-18442 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4316: zziplib security update (Low)
CVE-2020-8037 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4236: tcpdump security and bug fix update (Low)
CVE-2020-36314 low 2.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2021-43566 low 2.5 FIX sles rockydebian debian 5y ago RHBA-2021:4438: samba bug fix and enhancement update (Low)
CVE-2021-20269 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:4404: kexec-tools security, bug fix, and enhancement update (Low)
CVE-2020-13987 low 2.5 FIX slesdebian debian rhel 5y ago RHBA-2021:4446: iscsi-initiator-utils bug fix and enhancement update (Low)
CVE-2021-41973 unknown FIX debian debian 5y ago Infinite loop in Apache MINA
CVE-2020-16010 unknown 1.5 KEVFIX debian debian 5y ago Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a craft…
CVE-2020-0041 unknown 1.5 KEVFIX debian debian 5y ago Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was ob…
CVE-2019-2215 unknown 2.5 KEVEXPFIX debian debian 5y ago Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-…
CVE-2019-15752 unknown 2.5 KEVEXPFIX debian debian 5y ago Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop…
CVE-2016-3718 unknown 2.5 KEVEXPFIX debian debian 5y ago ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.
CVE-2016-3715 unknown 2.5 KEVEXPFIX debian debian 5y ago ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.
CVE-2021-41184 unknown FIX slesdebian debian 5y ago XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2021-41183 unknown FIX slesdebian debian 5y ago XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2021-41182 unknown FIX slesdebian debian 5y ago XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-28170 unknown debian debian 5y ago Improper Input Validation in Jakarta Expression Language
CVE-2021-3828 low 2.5 FIX arch archdebian debian 5y ago nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2020-7692 unknown FIX debian debian 5y ago Improper Authorization in Google OAuth Client
CVE-2021-25740 low 3.1 3.1 FIX arch arch slesdebian debian kubernetes 5y ago A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
CVE-2021-40690 unknown FIX debian debian 5y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
CVE-2021-41079 unknown FIX slesdebian debian 5y ago Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a spec…
CVE-2021-39239 unknown FIX debian debian 5y ago XML External Entity Reference in Apache Jena
CVE-2021-41303 unknown debian debian 5y ago Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
CVE-2021-40839 low 2.5 FIX arch archdebian debian 5y ago The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
CVE-2021-25737 low 2.5 FIX arch arch slesdebian debian 5y ago A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or …
CVE-2021-23437 low 2.5 FIX arch arch slesdebian debian 5y ago The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
CVE-2020-6950 unknown FIX debian debian 5y ago Directory traversal in Eclipse Mojarra
CVE-2021-39134 unknown FIX slesdebian debian 5y ago `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contract…
CVE-2021-39135 unknown FIX slesdebian debian 5y ago `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts …
CVE-2021-39139 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39140 unknown FIX slesdebian debian 5y ago XStream can cause a Denial of Service
CVE-2021-39141 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39144 unknown 2.5 KEVEXPFIX slesdebian debian 5y ago XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command o…
CVE-2021-39145 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39146 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39147 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39148 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39149 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39150 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-39151 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39152 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-39153 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39154 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-37714 unknown FIX slesdebian debian 5y ago Uncaught Exception in jsoup
CVE-2020-15522 unknown FIX debian debian sles 5y ago Timing based private key exposure in Bouncy Castle
CVE-2021-33192 unknown FIX debian debian 5y ago Cross-site scripting in Apache Jena Fuseki
CVE-2021-30640 unknown FIX slesdebian debian 5y ago A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This…
CVE-2021-33037 unknown FIX slesdebian debian 5y ago Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request…
CVE-2021-30639 unknown FIX debian debian 5y ago A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the e…
CVE-2021-22918 low 2.5 FIX arch arch rockydebian debian 5y ago Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whethe…
CVE-2021-3652 low 2.5 FIX debian debianarch arch sles 5y ago RHSA-2021:3079: 389-ds:1.4 security and bug fix update (Low)
CVE-2021-29063 low 2.5 FIX arch archdebian debian 5y ago A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 when the mpmathify function is called.
CVE-2021-35043 unknown FIX debian debian 5y ago Cross-site Scripting in OWASP AntiSamy
CVE-2021-36374 low 2.5 FIX debian debianarch arch sles 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-36373 low 2.5 FIX debian debianarch arch sles 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-36090 unknown FIX slesdebian debian 5y ago Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-35517 unknown FIX slesdebian debian 5y ago Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-35516 unknown FIX slesdebian debian 5y ago Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-35515 unknown FIX slesdebian debian 5y ago Excessive Iteration in Compress
CVE-2021-30129 unknown FIX debian debian 5y ago Buffer Overflow in Apache Mina SSHD
CVE-2019-25050 unknown FIX debian debian 5y ago netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and…
CVE-2021-34429 unknown 1.0 EXPFIX slesdebian debian 5y ago Encoded URIs can access WEB-INF directory in Eclipse Jetty
CVE-2021-38193 unknown FIX debian debian 5y ago An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.
CVE-2021-38191 unknown FIX debian debian 5y ago An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.
CVE-2021-34428 unknown FIX slesdebian debian 5y ago SessionListener can prevent a session from being invalidated breaking logout
CVE-2021-32693 unknown FIX debian debian 5y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prio…
CVE-2021-27807 unknown FIX slesdebian debian 5y ago Excessive Iteration Denial of Service in Apache PDFBox
CVE-2021-20220 unknown FIX debian debian 5y ago HTTP request smuggling in Undertow
CVE-2021-25122 unknown FIX slesdebian debian 5y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2021-26117 unknown FIX debian debian 5y ago Improper Authentication in Apache ActiveMQ and Apache Artemis
CVE-2021-23926 unknown FIX slesdebian debian 5y ago Improper Restriction of Recursive Entity References in Apache XMLBeans
CVE-2020-10688 unknown FIX debian debian 5y ago Cross-site scripting in RESTEasy
CVE-2021-31811 unknown FIX slesdebian debian 5y ago Uncontrolled memory consumption