Search

Found 16,952 results in 1013ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-29505 unknown FIX slesdebian debian 5y ago XStream is vulnerable to a Remote Command Execution attack
CVE-2021-29499 unknown FIX debian debian 5y ago SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the…
CVE-2019-13126 unknown FIX debian debian 5y ago An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authe…
CVE-2020-9283 unknown 1.0 EXPFIX debian debian 5y ago golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accept…
CVE-2021-27906 unknown FIX slesdebian debian 5y ago Uncontrolled Memory Allocation in Apache PDFBox
CVE-2021-21424 unknown FIX debian debian 5y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling de…
CVE-2021-23368 unknown FIX debian debian 5y ago The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
CVE-2021-28657 unknown slesdebian debian 5y ago Infinite loop in Apache Tika
CVE-2020-13933 unknown FIX debian debian 5y ago Authentication bypass in Apache Shiro
CVE-2020-1951 unknown FIX slesdebian debian 5y ago Infinite Loop in Apache Tika
CVE-2020-1950 unknown FIX slesdebian debian 5y ago Uncontrolled Resource Consumption in Apache Tika
CVE-2020-9489 unknown slesdebian debian 5y ago Missing Release of Memory after Effective Lifetime in Apache Tika
CVE-2020-1957 unknown FIX debian debian 5y ago Improper Authentication in Apache Shiro
CVE-2020-11989 unknown FIX debian debian 5y ago Improper Authentication in Apache Shiro
CVE-2020-5421 unknown FIX debian debian 5y ago Improper Input Validation in Spring Framework
CVE-2020-10687 unknown FIX debian debian 5y ago HTTP Request Smuggling in Undertow
CVE-2020-10705 unknown FIX debian debian 5y ago Allocation of Resources Without Limits or Throttling in Undertow
CVE-2020-10719 unknown FIX debian debian 5y ago HTTP Request Smuggling in Undertow
CVE-2020-26939 unknown FIX debian debian 5y ago Observable Differences in Behavior to Error Inputs in Bouncy Castle
CVE-2020-17510 unknown FIX debian debian 5y ago Authentication bypass in Apache Shiro
CVE-2021-23369 unknown FIX debian debian 5y ago Remote code execution in handlebars when compiling templates
CVE-2021-28163 unknown FIX slesdebian debian 5y ago Directory exposure in jetty
CVE-2021-28164 unknown 1.0 EXPFIX slesdebian debian 5y ago Authorization Before Parsing and Canonicalization in jetty
CVE-2021-21388 unknown FIX debian debian 5y ago systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has…
CVE-2020-8908 unknown FIX slesdebian debian google 5y ago Information Disclosure in Guava
CVE-2021-21351 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21350 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21349 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21348 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
CVE-2021-21347 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21346 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21345 unknown FIX slesdebian debian 5y ago XStream is vulnerable to a Remote Command Execution attack
CVE-2021-21344 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21343 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
CVE-2021-21342 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21341 unknown FIX slesdebian debian 5y ago XStream can cause a Denial of Service.
CVE-2021-25329 unknown FIX slesdebian debian 5y ago The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikel…
CVE-2020-13959 unknown FIX debian debian 5y ago Cross-site scripting (XSS) in Apache Velocity Tools
CVE-2020-27223 unknown FIX slesdebian debian 5y ago DOS vulnerability for Quoted Quality CSV headers
CVE-2020-25649 unknown FIX slesdebian debian 5y ago XML External Entity (XXE) Injection in Jackson Databind
CVE-2021-21315 unknown 1.5 KEVFIX debian debian 5y ago The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation b…
CVE-2021-21311 unknown 1.5 KEVFIX debian debian 5y ago Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.
CVE-2021-21239 critical 9.5 FIX arch arch slesdebian debian 5y ago PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default C…
CVE-2021-21238 critical 9.5 FIX arch arch slesdebian debian 5y ago PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to valid…
CVE-2021-20190 unknown FIX slesdebian debian 5y ago Deserialization of untrusted data in jackson-databind
CVE-2020-16044 critical 9.5 FIX arch arch slesdebian debian 6y ago Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
CVE-2020-26258 unknown FIX slesdebian debian 6y ago Server-Side Forgery Request can be activated unmarshalling with XStream
CVE-2020-26259 unknown FIX slesdebian debian 6y ago XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
CVE-2020-26274 unknown FIX debian debian 6y ago In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.
CVE-2020-26271 critical 9.5 FIX arch archdebian debian 6y ago In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memory while building the computation graph. The MakeEdge function creates an edge …
CVE-2020-26270 critical 9.5 FIX arch archdebian debian 6y ago In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a q…
CVE-2020-26268 critical 9.5 FIX arch archdebian debian 6y ago In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memory mapped file which is assumed immutable. However, if the type of the tensor i…
CVE-2020-26267 critical 9.5 FIX arch archdebian debian 6y ago In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_format attributes. The code assumes that these two arguments define a permutation o…
CVE-2020-26266 critical 9.5 FIX arch archdebian debian 6y ago In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default …
CVE-2020-16009 critical 10.0 KEVFIX arch archdebian debian 6y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2020-27218 unknown FIX slesdebian debian 6y ago Buffer not correctly recycled in Gzip Request inflation
CVE-2020-26968 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
CVE-2020-26965 critical 9.5 FIX arch arch slesdebian debian 6y ago Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remember…
CVE-2020-26961 critical 9.5 FIX arch arch slesdebian debian 6y ago When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped…
CVE-2020-26960 critical 9.5 FIX arch arch slesdebian debian 6y ago If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerabili…
CVE-2020-26959 critical 9.5 FIX arch arch slesdebian debian 6y ago During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerabil…
CVE-2020-26958 critical 9.5 FIX arch arch slesdebian debian 6y ago Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerabili…
CVE-2020-26956 critical 9.5 FIX arch arch slesdebian debian 6y ago In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbir…
CVE-2020-26953 critical 9.5 FIX arch arch slesdebian debian 6y ago It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerabilit…
CVE-2020-26951 critical 9.5 FIX arch arch slesdebian debian 6y ago A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privilege…
CVE-2020-16012 critical 9.5 FIX arch archdebian debian sles 6y ago Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2020-26245 unknown FIX debian debian 6y ago npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper poll…
CVE-2020-26237 unknown FIX debian debian 6y ago Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will …
CVE-2020-26217 unknown FIX slesdebian debian 6y ago XStream can be used for Remote Code Execution
CVE-2020-26950 critical 10.0 EXPFIX arch arch slesdebian debian 6y ago In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox …
CVE-2020-27216 unknown FIX debian debian 6y ago Local Temp Directory Hijacking Vulnerability
CVE-2020-35922 unknown FIX slesdebian debian 6y ago An issue was discovered in the mio crate before 0.7.6 for Rust. It has false expectations about the std::net::SocketAddr memory representation.
CVE-2020-26300 unknown FIX debian debian 6y ago systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fix…
CVE-2020-7752 unknown FIX debian debian 6y ago This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execu…
CVE-2020-15999 critical 10.0 KEVFIX arch arch slesdebian debian 6y ago Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded int…
CVE-2020-15969 critical 9.5 FIX arch archdebian debian sles 6y ago Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-15683 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2020-14803 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-14782 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-14781 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-24660 unknown FIX debian debian 6y ago An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also af…
CVE-2020-15094 unknown FIX debian debian 6y ago In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X…
CVE-2020-12390 critical 9.5 FIX arch archdebian debian rhel 6y ago Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.
CVE-2019-17638 unknown FIX debian debian 6y ago Operation on a Resource after Expiration or Release in Jetty Server
CVE-2019-17023 critical 9.5 FIX arch archdebian debian rocky 6y ago After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state,…
CVE-2019-11756 critical 9.5 FIX arch archdebian debian rocky 6y ago Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.
CVE-2019-13990 unknown FIX slesdebian debian 6y ago XML external entity injection in Terracotta Quartz Scheduler
CVE-2017-7957 unknown FIX slesdebian debian 6y ago Denial of service in XStream
CVE-2016-3674 unknown FIX debian debian 6y ago XML External Entity Injection in XStream
CVE-2018-5968 unknown FIX slesdebian debian 6y ago Deserialization of Untrusted Data in jackson-databind
CVE-2020-15254 critical 9.5 FIX arch archdebian debian 6y ago Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as th…
CVE-2020-14061 unknown FIX debian debian 6y ago Deserialization of untrusted data in Jackson Databind
CVE-2020-14195 unknown FIX debian debian 6y ago Deserialization of untrusted data in Jackson Databind
CVE-2018-10237 unknown FIX slesdebian debian 6y ago Denial of Service in Google Guava
CVE-2017-7536 unknown FIX debian debian 6y ago Privilege Escalation in Hibernate Validator
CVE-2020-11612 unknown FIX slesdebian debian 6y ago Denial of Service in Netty
CVE-2018-15756 unknown FIX debian debian 6y ago Denial of Service in Spring Framework
CVE-2009-2625 unknown FIX debian debian 6y ago Denial of service in Apache Xerces2
CVE-2018-12023 unknown FIX debian debian 6y ago Deserialization of Untrusted Data
CVE-2019-17267 unknown FIX slesdebian debian 6y ago Improper Input Validation in jackson-databind