Search

Found 15,834 results in 5318ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2018-19360 unknown FIX debian debian 8y ago Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization
CVE-2018-14718 unknown FIX debian debian 8y ago Arbitrary Code Execution in jackson-databind
CVE-2018-17197 unknown FIX slesdebian debian 8y ago Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3Parser
CVE-2018-17187 unknown FIX debian debian 8y ago Improper Certificate Validation in proton-j
CVE-2018-1337 unknown FIX debian debian 8y ago In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connec…
CVE-2018-8006 unknown FIX debian debian 8y ago Apache ActiveMQ web console vulnerable to Cross-site Scripting
CVE-2017-2666 unknown FIX debian debian 8y ago Undertow-core vulnerable to HTTP Request Smuggling
CVE-2017-2670 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects io.undertow:undertow-core
CVE-2018-10936 unknown FIX slesdebian debian 8y ago Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregate
CVE-2018-11775 unknown FIX debian debian 8y ago Improper Certificate Validation in Apache activemq-client
CVE-2018-11771 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.apache.commons:commons-compress
CVE-2017-7658 unknown FIX debian debian 8y ago Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)
CVE-2017-7656 unknown FIX debian debian 8y ago Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)
CVE-2018-12536 unknown FIX debian debian 8y ago Eclipse Jetty Server generates error message containing sensitive information
CVE-2017-7657 unknown FIX debian debian 8y ago Critical severity vulnerability that affects org.eclipse.jetty:jetty-server
CVE-2016-1000345 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
CVE-2016-1000344 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode
CVE-2017-17485 unknown FIX debian debian 8y ago jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass
CVE-2017-15095 unknown FIX debian debian 8y ago jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution
CVE-2018-1275 unknown FIX debian debian 8y ago Spring Framework has Improperly Implemented Security Check for Standard
CVE-2018-1272 unknown FIX debian debian 8y ago Possible privilege escalation in org.springframework:spring-core
CVE-2018-1271 unknown FIX debian debian 8y ago Path Traversal in org.springframework:spring-core
CVE-2018-1270 unknown FIX debian debian 8y ago Spring Framework allows applications to expose STOMP over WebSocket endpoints
CVE-2018-1257 unknown FIX debian debian 8y ago Denial of Service in org.springframework:spring-core
CVE-2018-1199 unknown FIX debian debian 8y ago Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
CVE-2018-8010 unknown FIX debian debian 8y ago There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
CVE-2018-1308 unknown FIX debian debian 8y ago There is a XML external entity expansion (XXE) vulnerability in Apache Solr
CVE-2018-8026 unknown FIX debian debian 8y ago XML external entity expansion in org.apache.solr:solr-core
CVE-2018-11797 unknown FIX slesdebian debian 8y ago In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
CVE-2018-1336 unknown FIX slesdebian debian 8y ago An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 t…
CVE-2018-1305 unknown FIX slesdebian debian 8y ago Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. …
CVE-2018-1304 unknown FIX slesdebian debian 8y ago The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 …
CVE-2016-1000352 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the ECIES implementation allowed the use of ECB mode
CVE-2016-1000346 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the other party DH public key is not fully validated
CVE-2016-1000343 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values
CVE-2016-1000342 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verification
CVE-2016-1000341 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
CVE-2016-1000340 unknown FIX debian debian 8y ago The Bouncy Castle JCE Provider carry a propagation bug
CVE-2016-1000339 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
CVE-2016-1000338 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate
CVE-2018-1000613 unknown FIX debian debian sles 8y ago Deserialization of Untrusted Data in Bouncy castle
CVE-2018-1338 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.apache.tika:tika-core
CVE-2018-8017 unknown FIX slesdebian debian 8y ago Comparison errorr in org.apache.tika:tika-core
CVE-2018-11762 unknown FIX slesdebian debian 8y ago Moderate severity vulnerability that affects org.apache.tika:tika-core
CVE-2018-11761 unknown FIX slesdebian debian 8y ago High severity vulnerability that affects org.apache.tika:tika-core
CVE-2018-1339 unknown FIX debian debian 8y ago org.apache.tika:tika-parsers has an Infinite Loop vulnerability
CVE-2018-1335 unknown 1.0 EXPFIX debian debian 8y ago Command injection in org.apache.tika:tika-core
CVE-2018-11796 unknown FIX slesdebian debian 8y ago Apache Tika is vulnerable to entity expansions which can lead to a denial of service attack
CVE-2018-8032 unknown FIX debian debian sles 8y ago Moderate severity vulnerability that affects apache axis
CVE-2018-7489 unknown FIX debian debian 8y ago FasterXML jackson-databind allows unauthenticated remote code execution
CVE-2018-1000180 unknown FIX debian debian sles 8y ago Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
CVE-2018-12538 unknown FIX debian debian 8y ago Access and integrity issue within Eclipse Jetty
CVE-2018-11040 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.springframework:spring-core
CVE-2018-11039 unknown FIX debian debian 8y ago Spring Framework Cross Site Tracing (XST)
CVE-2017-7525 unknown FIX debian debian 8y ago jackson-databind is vulnerable to a deserialization flaw
CVE-2018-1000632 unknown FIX slesdebian debian 8y ago Dom4j contains a XML Injection vulnerability
CVE-2018-1000807 unknown FIX slesdebian debian 8y ago Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possibl…
CVE-2018-1000808 unknown FIX slesdebian debian 8y ago Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denia…
CVE-2018-14041 unknown FIX debian debian 8y ago Bootstrap Cross-site Scripting vulnerability
CVE-2018-20997 unknown FIX debian debian 8y ago An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
CVE-2017-17864 low 3.3 3.3 FIX arch archdebian debian linux-kernel 9y ago kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentia…
CVE-2017-17807 low 3.3 3.3 FIX arch arch slesdebian debian 9y ago The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing …
CVE-2017-15897 low 3.1 3.1 FIX debian debian nodejs 9y ago Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This…
CVE-2017-17433 low 3.7 3.7 FIX arch arch slesdebian debian samba 9y ago The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_f…
CVE-2017-8822 low 3.7 3.7 FIX arch archdebian debian tor_project 9y ago In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick th…
CVE-2017-16229 unknown FIX debian debian 9y ago In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse.
CVE-2017-5081 low 3.3 3.3 FIX arch arch rhelmacos macos google 9y ago multiple issues in chromium
CVE-2017-15096 low 3.3 3.3 FIX debian debian gluster 9y ago A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
CVE-2012-3866 low 2.1 FIX debian debian puppetpuppetlabs 9y ago lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration in…
CVE-2012-3865 low 3.5 FIX debian debian puppetpuppetlabs 9y ago Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remot…
CVE-2012-3408 low 2.6 FIX debian debian puppetpuppetlabs 9y ago lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote att…
CVE-2012-1989 low 3.6 FIX debian debian puppetpuppetlabs 9y ago telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connect…
CVE-2017-10345 low 3.1 3.1 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE…
CVE-2017-3653 low 3.1 3.1 slesdebian debian rhel oracleredhatmariadb 9y ago Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Diffic…
CVE-2017-10193 low 3.1 3.1 FIX slesdebian debian rhel oraclenetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131.…
CVE-2017-8933 low 3.3 3.3 FIX debian debian libmenu-cache_project 9y ago Libmenu-cache 1.0.2 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (menu unavailability).
CVE-2017-7995 low 3.8 3.8 FIX slessuse susedebian debian suse 9y ago Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in th…
CVE-2017-8418 low 3.3 3.3 FIX debian debian rubocop_project 9y ago RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.
CVE-2017-3544 low 3.7 3.7 FIX slesdebian debian rhel oracleredhat 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embed…
CVE-2017-3539 low 3.1 3.1 FIX slesdebian debian rhel oracleredhat 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121.…
CVE-2017-3533 low 3.7 3.7 FIX slesdebian debian rhel oracleredhat 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embed…
CVE-2017-3513 low 2.5 2.5 FIX debian debian oracle 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Difficult to exploit v…
CVE-2014-9680 low 3.3 3.3 FIX slesdebian debian sudo_project 9y ago sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) b…
CVE-2016-10118 low 3.3 3.3 FIX arch archdebian debian firejail_project 9y ago Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.
CVE-2017-7407 low 2.4 2.4 FIX slesdebian debian haxx 9y ago The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a w…
CVE-2017-5930 low 2.7 3.7 EXPFIX suse susedebian debian postfixadmin_project 9y ago The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission ch…
CVE-2017-5985 low 3.3 3.3 FIX arch archdebian debian linuxcontainers 9y ago lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ow…
CVE-2015-2877 low 3.3 3.3 debian debian linux-kernel rhel 9y ago Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other …
CVE-2016-7553 low 3.3 3.3 FIX debian debian irssi 9y ago The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from …
CVE-2016-9085 low 3.3 3.3 FIX debian debianfedora fedora webmproject 10y ago Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
CVE-2017-3259 low 3.7 3.7 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112. Difficult to exploit vulnerability allow…
CVE-2016-8328 low 3.7 3.7 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unau…
CVE-2016-1551 low 3.7 3.7 FIX slesdebian debian ntpntpsec 10y ago ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference cloc…
CVE-2016-9932 low 3.3 3.3 FIX slesdebian debian 10y ago CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
CVE-2016-7429 low 3.7 3.7 FIX slesarch archdebian debian ntp 10y ago NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source)…
CVE-2016-9015 low 3.7 3.7 FIX slesdebian debian python 10y ago Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the l…
CVE-2016-4323 low 3.7 3.7 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or …
CVE-2016-2380 low 3.1 3.1 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced …
CVE-2016-9908 low 3.3 3.3 FIX slesdebian debian qemu 10y ago Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest use…
CVE-2016-10931 unknown FIX debian debian 10y ago An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for host…