Search

Found 15,824 results in 735ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-38191 unknown FIX debian debian 5y ago An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.
CVE-2021-34428 unknown FIX slesdebian debian 5y ago SessionListener can prevent a session from being invalidated breaking logout
CVE-2021-32693 unknown FIX debian debian 5y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prio…
CVE-2021-27807 unknown FIX slesdebian debian 5y ago Excessive Iteration Denial of Service in Apache PDFBox
CVE-2021-20220 unknown FIX debian debian 5y ago HTTP request smuggling in Undertow
CVE-2021-25122 unknown FIX slesdebian debian 5y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
CVE-2021-26117 unknown FIX debian debian 5y ago Improper Authentication in Apache ActiveMQ and Apache Artemis
CVE-2021-23926 unknown FIX slesdebian debian 5y ago Improper Restriction of Recursive Entity References in Apache XMLBeans
CVE-2020-10688 unknown FIX debian debian 5y ago Cross-site scripting in RESTEasy
CVE-2021-31811 unknown FIX slesdebian debian 5y ago Uncontrolled memory consumption
CVE-2021-31812 unknown FIX slesdebian debian 5y ago Infinite Loop in Apache PDFBox
CVE-2021-28169 unknown FIX slesdebian debian 5y ago Jetty Utility Servlets ConcatServlet Double Decoding Information Disclosure Vulnerability
CVE-2020-12690 unknown FIX slesdebian debian 5y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a key…
CVE-2020-25724 unknown FIX debian debian 5y ago Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
CVE-2020-14340 unknown FIX debian debian 5y ago Uncontrolled Resource Consumption in XNIO
CVE-2017-8761 unknown FIX debian debian 5y ago In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these log…
CVE-2021-29957 low 2.5 FIX arch arch sles rocky 5y ago multiple issues in thunderbird
CVE-2021-29956 low 2.5 FIX arch arch sles rocky 5y ago multiple issues in thunderbird
CVE-2020-10693 unknown FIX debian debian 5y ago Improper Input Validation in Hibernate Validator
CVE-2021-31542 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
CVE-2020-25633 unknown debian debian 5y ago Generation of Error Message Containing Sensitive Information in RESTEasy client
CVE-2021-26813 low 2.5 FIX arch archdebian debian 5y ago markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or de…
CVE-2014-9356 unknown FIX debian debian 5y ago Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or…
CVE-2021-29505 unknown FIX slesdebian debian 5y ago XStream is vulnerable to a Remote Command Execution attack
CVE-2021-29499 unknown FIX debian debian 5y ago SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the…
CVE-2019-13126 unknown FIX debian debian 5y ago An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authe…
CVE-2020-9283 unknown 1.0 EXPFIX debian debian 5y ago golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accept…
CVE-2021-20201 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:1924: spice security update (Low)
CVE-2019-17402 low 2.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1758: exiv2 security, bug fix, and enhancement update (Low)
CVE-2020-16117 low 2.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1752: evolution security, bug fix, and enhancement update (Low)
CVE-2021-23240 low 2.5 FIX arch arch sles rocky 5y ago selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary …
CVE-2021-23239 low 2.5 FIX arch arch sles rocky 5y ago The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled…
CVE-2020-36318 low 2.5 FIX arch arch sles rocky 5y ago In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or doub…
CVE-2020-36317 low 2.5 FIX arch arch sles rocky 5y ago In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could res…
CVE-2019-18276 low 2.5 FIX debian debian sles rhel 5y ago RHSA-2021:1679: bash security and bug fix update (Low)
CVE-2021-27906 unknown FIX slesdebian debian 5y ago Uncontrolled Memory Allocation in Apache PDFBox
CVE-2021-21424 unknown FIX debian debian 5y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling de…
CVE-2021-23368 unknown FIX debian debian 5y ago The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
CVE-2021-28657 unknown slesdebian debian 5y ago Infinite loop in Apache Tika
CVE-2020-13933 unknown FIX debian debian 5y ago Authentication bypass in Apache Shiro
CVE-2020-1951 unknown FIX slesdebian debian 5y ago Infinite Loop in Apache Tika
CVE-2020-1950 unknown FIX slesdebian debian 5y ago Uncontrolled Resource Consumption in Apache Tika
CVE-2020-9489 unknown slesdebian debian 5y ago Missing Release of Memory after Effective Lifetime in Apache Tika
CVE-2020-1957 unknown FIX debian debian 5y ago Improper Authentication in Apache Shiro
CVE-2020-11989 unknown FIX debian debian 5y ago Improper Authentication in Apache Shiro
CVE-2020-5421 unknown FIX debian debian 5y ago Improper Input Validation in Spring Framework
CVE-2020-10687 unknown FIX debian debian 5y ago HTTP Request Smuggling in Undertow
CVE-2020-10705 unknown FIX debian debian 5y ago Allocation of Resources Without Limits or Throttling in Undertow
CVE-2020-10719 unknown FIX debian debian 5y ago HTTP Request Smuggling in Undertow
CVE-2020-26939 unknown FIX debian debian 5y ago Observable Differences in Behavior to Error Inputs in Bouncy Castle
CVE-2020-17510 unknown FIX debian debian 5y ago Authentication bypass in Apache Shiro
CVE-2020-29651 low 2.5 FIX arch arch slesdebian debian 5y ago A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying …
CVE-2021-27919 low 2.5 FIX arch arch slesdebian debian 5y ago archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any fi…
CVE-2021-23369 unknown FIX debian debian 5y ago Remote code execution in handlebars when compiling templates
CVE-2021-28658 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were no…
CVE-2021-28163 unknown FIX slesdebian debian 5y ago Directory exposure in jetty
CVE-2021-28164 unknown 1.0 EXPFIX slesdebian debian 5y ago Authorization Before Parsing and Canonicalization in jetty
CVE-2021-21388 unknown FIX debian debian 5y ago systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has…
CVE-2020-8908 unknown FIX slesdebian debian google 5y ago Information Disclosure in Guava
CVE-2021-21351 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21350 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21349 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21348 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
CVE-2021-21347 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21346 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21345 unknown FIX slesdebian debian 5y ago XStream is vulnerable to a Remote Command Execution attack
CVE-2021-21344 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21343 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
CVE-2021-21342 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21341 unknown FIX slesdebian debian 5y ago XStream can cause a Denial of Service.
CVE-2021-25329 unknown FIX slesdebian debian 5y ago The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikel…
CVE-2021-3281 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal …
CVE-2020-13959 unknown FIX debian debian 5y ago Cross-site scripting (XSS) in Apache Velocity Tools
CVE-2020-27223 unknown FIX slesdebian debian 5y ago DOS vulnerability for Quoted Quality CSV headers
CVE-2021-21330 low 2.5 FIX arch arch slesdebian debian 5y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based…
CVE-2020-25649 unknown FIX slesdebian debian 5y ago XML External Entity (XXE) Injection in Jackson Databind
CVE-2021-21315 unknown 1.5 KEVFIX debian debian 5y ago The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation b…
CVE-2021-21311 unknown 1.5 KEVFIX debian debian 5y ago Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.
CVE-2021-20190 unknown FIX slesdebian debian 5y ago Deserialization of untrusted data in jackson-databind
CVE-2021-21236 low 2.5 FIX debian debianarch arch 6y ago CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When process…
CVE-2020-26258 unknown FIX slesdebian debian 6y ago Server-Side Forgery Request can be activated unmarshalling with XStream
CVE-2020-26259 unknown FIX slesdebian debian 6y ago XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
CVE-2020-26274 unknown FIX debian debian 6y ago In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.
CVE-2020-27218 unknown FIX slesdebian debian 6y ago Buffer not correctly recycled in Gzip Request inflation
CVE-2020-26245 unknown FIX debian debian 6y ago npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper poll…
CVE-2020-26237 unknown FIX debian debian 6y ago Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will …
CVE-2020-26217 unknown FIX slesdebian debian 6y ago XStream can be used for Remote Code Execution
CVE-2020-27216 unknown FIX debian debian 6y ago Local Temp Directory Hijacking Vulnerability
CVE-2020-3898 low 2.5 FIX debian debian sles rocky 6y ago RHSA-2020:4469: cups security and bug fix update (Low)
CVE-2020-11736 low 2.5 FIX arch arch slesdebian debian 6y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2019-20386 low 2.5 FIX slesdebian debian rhel 6y ago An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
CVE-2019-17450 low 2.5 FIX debian debian sles rhel 6y ago RHSA-2020:4465: binutils security update (Low)
CVE-2019-16167 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:4638: sysstat security update (Low)
CVE-2019-1551 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4514: openssl security, bug fix, and enhancement update (Low)
CVE-2020-14928 low 2.5 FIX slesdebian debian rocky 6y ago RHSA-2020:4649: evolution security and bug fix update (Low)
CVE-2019-14494 low 2.5 FIX slesdebian debian rhel 6y ago An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
CVE-2020-12803 low 2.5 FIX arch arch sles rocky 6y ago ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable f…
CVE-2020-12802 low 2.5 FIX arch arch sles rocky 6y ago LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
CVE-2019-15165 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4547: libpcap security, bug fix, and enhancement update (Low)
CVE-2020-10759 low 2.5 FIX arch arch slesdebian debian 6y ago A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practi…