Search

Found 18,501 results in 4143ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-53990 unknown debian debian 2y ago AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
CVE-2024-36623 unknown FIX debian debian sles 2y ago moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application cr…
CVE-2024-36621 unknown FIX debian debian sles 2y ago moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function result…
CVE-2024-36620 unknown FIX debian debian 2y ago moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-27043 low 2.5 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: media: edia: dvbdev: fix a use-after-free In dvb_register_device, *pdvbdev is set equal to dvbdev, which is freed in several erro…
CVE-2024-53916 unknown FIX debian debian 2y ago In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileg…
CVE-2024-44308 unknown 1.5 KEVFIX slesdebian debian 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing malici…
CVE-2024-52304 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request s…
CVE-2024-52303 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError…
CVE-2024-52318 unknown FIX slesdebian debian 2y ago Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97…
CVE-2024-52317 unknown FIX slesdebian debian 2y ago Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between us…
CVE-2024-52316 unknown FIX slesdebian debian 2y ago Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception dur…
CVE-2024-38828 unknown debian debian 2y ago Spring MVC controller vulnerable to a DoS attack
CVE-2023-4639 unknown FIX debian debian 2y ago Undertow incorrectly parses cookies
CVE-2018-12699 low 2.5 FIX debian debian sles rocky 2y ago RHSA-2024:9689: binutils security update (Low)
CVE-2024-51996 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted i…
CVE-2024-47535 unknown FIX slesdebian debian 2y ago Denial of Service attack on windows app using netty
CVE-2024-6501 low 2.5 FIX rhel slesdebian debian 2y ago Low: NetworkManager security update
CVE-2024-6126 low 2.5 FIX rheldebian debian sles 2y ago A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
CVE-2024-5742 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:6986: nano security update (Low)
CVE-2024-5535 critical 9.1 9.1 FIX rhel rocky sles 2y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-4741 low 2.5 FIX rhel sles rocky 2y ago Low: openssl security update
CVE-2024-4603 low 2.5 FIX rhel sles rocky 2y ago Low: openssl security update
CVE-2024-38612 critical 9.8 9.8 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defin…
CVE-2024-29039 low 2.5 FIX rhel sles rocky 2y ago Low: tpm2-tools security update
CVE-2024-29038 low 2.5 FIX rhel sles rocky 2y ago Low: tpm2-tools security update
CVE-2024-26461 low 2.5 rhel sles rocky 2y ago RHSA-2024:3268: krb5 security update (Low)
CVE-2024-26458 low 2.5 rhel rocky sles 2y ago RHSA-2024:3268: krb5 security update (Low)
CVE-2024-2314 low 2.5 FIX rheldebian debian rocky 2y ago RHSA-2024:8831: bcc security update (Low)
CVE-2024-2313 low 2.5 FIX rheldebian debian rocky 2y ago RHSA-2024:8830: bpftrace security update (Low)
CVE-2021-3903 low 2.5 FIX rhelarch arch sles 2y ago vim is vulnerable to Heap-based Buffer Overflow
CVE-2024-47072 unknown FIX slesdebian debian 2y ago XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
CVE-2024-51504 unknown FIX debian debian 2y ago Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
CVE-2023-1973 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2023-1932 unknown debian debian 2y ago hibernate-validator Cross-site Scripting vulnerability
CVE-2024-51755 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property polic…
CVE-2024-51754 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of …
CVE-2024-51736 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory i…
CVE-2024-50345 unknown FIX debian debian 2y ago symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters t…
CVE-2024-50343 unknown FIX debian debian 2y ago symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metachar…
CVE-2024-50342 unknown FIX debian debian 2y ago symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, so…
CVE-2024-50341 unknown FIX debian debian 2y ago symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` define…
CVE-2024-50340 unknown FIX debian debian 2y ago symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any…
CVE-2024-51746 unknown FIX debian debian 2y ago Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are …
CVE-2024-48910 unknown FIX debian debian 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CVE-2024-36387 low 2.5 FIX debian debian rhel sles 2y ago Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
CVE-2024-48063 unknown debian debian 2y ago In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVE-2024-49760 unknown FIX debian debian 2y ago OpenRefine has a path traversal in LoadLanguageCommand
CVE-2024-47883 unknown FIX debian debian 2y ago Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
CVE-2024-47882 unknown FIX debian debian 2y ago OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
CVE-2024-47881 unknown FIX debian debian 2y ago OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
CVE-2024-47880 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) from POST request in ExportRowsCommand
CVE-2024-47879 unknown FIX debian debian 2y ago OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
CVE-2024-47878 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
CVE-2024-37383 unknown 2.5 KEVEXPFIX debian debian 2y ago RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
CVE-2024-38820 unknown debian debian 2y ago Spring Framework DataBinder Case Sensitive Match Exception
CVE-2024-45217 unknown FIX debian debian 2y ago Insecure Default Initialization of Resource vulnerability in Apache Solr
CVE-2024-45216 unknown FIX debian debian 2y ago Improper Authentication vulnerability in Apache Solr
CVE-2024-49195 critical 9.8 9.8 FIX slesdebian debian trustedfirmware 2y ago Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
CVE-2024-47874 unknown FIX slesdebian debian 2y ago Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buff…
CVE-2024-6763 unknown debian debian sles 2y ago Eclipse Jetty URI parsing of invalid authority
CVE-2024-8184 unknown FIX debian debian sles 2y ago Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
CVE-2024-6762 unknown FIX debian debian sles 2y ago Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
CVE-2024-9823 unknown FIX debian debian sles 2y ago Eclipse Jetty has a denial of service vulnerability on DosFilter
CVE-2024-28168 unknown FIX debian debian sles 2y ago Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability
CVE-2024-45231 unknown FIX slesdebian debian 2y ago An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to…
CVE-2024-45230 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via ve…
CVE-2024-47211 unknown FIX debian debian 2y ago In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when…
CVE-2024-47855 unknown FIX slesdebian debian 2y ago JSON-lib mishandles an unbalanced comment string
CVE-2024-47554 unknown FIX debian debian sles 2y ago Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
CVE-2024-47534 unknown FIX debian debian 2y ago go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", th…
CVE-2024-47175 low 3.5 EXPFIX rhel rockydebian debian 2y ago Low: cups security update
CVE-2024-38809 unknown debian debian 2y ago Spring Framework DoS via conditional HTTP request
CVE-2024-7254 unknown FIX slesdebian debian 2y ago protobuf-java has potential Denial of Service issue
CVE-2024-45492 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:6989: expat security update (Moderate)
CVE-2024-45491 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:8859: xmlrpc-c security update (Moderate)
CVE-2024-45801 unknown FIX debian debian 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking ad…
CVE-2024-38816 unknown debian debian 2y ago Path traversal vulnerability in functional web frameworks
CVE-2024-45411 unknown FIX debian debian 2y ago Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability i…
CVE-2024-45296 unknown FIX debian debianubuntu ubuntu 2y ago Path-to-Regexp vulnerability
CVE-2017-1000253 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
CVE-2016-3714 unknown 2.5 KEVEXPFIX debian debian 2y ago ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code v…
CVE-2024-45405 unknown FIX slesdebian debian 2y ago `gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a…
CVE-2024-45159 critical 9.8 9.8 FIX debian debian trustedfirmware 2y ago An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in…
CVE-2024-45158 critical 9.8 9.8 FIX debian debian trustedfirmware 2y ago An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest…
CVE-2024-37371 critical 9.1 9.1 FIX rhelarch arch rocky mit 2y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-45305 unknown FIX slesdebian debian 2y ago gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to find the path of a configuration file that belongs to the `git` installation its…
CVE-2024-43805 unknown FIX slesdebian debian 2y ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious n…
CVE-2024-7965 unknown 1.5 KEVFIX debian debian 2y ago Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-43788 unknown FIX slesdebian debian 2y ago Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. Th…
CVE-2024-7971 unknown 1.5 KEVFIX debian debian 2y ago Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-38807 unknown debian debian 2y ago Signature forgery in Spring Boot's Loader
CVE-2024-7885 unknown FIX debian debian 2y ago Undertow vulnerable to Race Condition
CVE-2024-38808 unknown debian debian 2y ago Spring Framework vulnerable to Denial of Service
CVE-2024-35845 critical 9.1 9.1 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-42367 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.g…
CVE-2024-42005 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a c…
CVE-2024-41991 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service…
CVE-2024-41990 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs wit…
CVE-2024-41989 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number i…