Search

Found 17,004 results in 3620ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-1000344 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode
CVE-2017-17485 unknown FIX debian debian 8y ago jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass
CVE-2017-15095 unknown FIX debian debian 8y ago jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution
CVE-2018-1275 unknown FIX debian debian 8y ago Spring Framework has Improperly Implemented Security Check for Standard
CVE-2018-1272 unknown FIX debian debian 8y ago Possible privilege escalation in org.springframework:spring-core
CVE-2018-1271 unknown FIX debian debian 8y ago Path Traversal in org.springframework:spring-core
CVE-2018-1270 unknown FIX debian debian 8y ago Spring Framework allows applications to expose STOMP over WebSocket endpoints
CVE-2018-1257 unknown FIX debian debian 8y ago Denial of Service in org.springframework:spring-core
CVE-2018-1199 unknown FIX debian debian 8y ago Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
CVE-2018-8010 unknown FIX debian debian 8y ago There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
CVE-2018-1308 unknown FIX debian debian 8y ago There is a XML external entity expansion (XXE) vulnerability in Apache Solr
CVE-2018-8026 unknown FIX debian debian 8y ago XML external entity expansion in org.apache.solr:solr-core
CVE-2018-11797 unknown FIX slesdebian debian 8y ago In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
CVE-2018-1336 unknown FIX slesdebian debian 8y ago An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 t…
CVE-2018-1305 unknown FIX slesdebian debian 8y ago Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. …
CVE-2018-1304 unknown FIX slesdebian debian 8y ago The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 …
CVE-2016-1000352 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the ECIES implementation allowed the use of ECB mode
CVE-2016-1000346 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the other party DH public key is not fully validated
CVE-2016-1000343 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values
CVE-2016-1000342 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verification
CVE-2016-1000341 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
CVE-2016-1000340 unknown FIX debian debian 8y ago The Bouncy Castle JCE Provider carry a propagation bug
CVE-2016-1000339 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
CVE-2016-1000338 unknown FIX debian debian 8y ago In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate
CVE-2018-1000613 unknown FIX debian debian sles 8y ago Deserialization of Untrusted Data in Bouncy castle
CVE-2018-1338 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.apache.tika:tika-core
CVE-2018-8017 unknown FIX slesdebian debian 8y ago Comparison errorr in org.apache.tika:tika-core
CVE-2018-11762 unknown FIX slesdebian debian 8y ago Moderate severity vulnerability that affects org.apache.tika:tika-core
CVE-2018-11761 unknown FIX slesdebian debian 8y ago High severity vulnerability that affects org.apache.tika:tika-core
CVE-2018-1339 unknown FIX debian debian 8y ago org.apache.tika:tika-parsers has an Infinite Loop vulnerability
CVE-2018-1335 unknown 1.0 EXPFIX debian debian 8y ago Command injection in org.apache.tika:tika-core
CVE-2018-11796 unknown FIX slesdebian debian 8y ago Apache Tika is vulnerable to entity expansions which can lead to a denial of service attack
CVE-2018-8032 unknown FIX debian debian sles 8y ago Moderate severity vulnerability that affects apache axis
CVE-2018-7489 unknown FIX debian debian 8y ago FasterXML jackson-databind allows unauthenticated remote code execution
CVE-2018-1000180 unknown FIX debian debian sles 8y ago Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
CVE-2018-12538 unknown FIX debian debian 8y ago Access and integrity issue within Eclipse Jetty
CVE-2018-11040 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects org.springframework:spring-core
CVE-2018-11039 unknown FIX debian debian 8y ago Spring Framework Cross Site Tracing (XST)
CVE-2017-7525 unknown FIX debian debian 8y ago jackson-databind is vulnerable to a deserialization flaw
CVE-2018-1000632 unknown FIX slesdebian debian 8y ago Dom4j contains a XML Injection vulnerability
CVE-2018-1000807 unknown FIX slesdebian debian 8y ago Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possibl…
CVE-2018-1000808 unknown FIX slesdebian debian 8y ago Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denia…
CVE-2018-10895 critical 9.5 FIX arch archdebian debian 8y ago qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/s…
CVE-2018-14041 unknown FIX debian debian 8y ago Bootstrap Cross-site Scripting vulnerability
CVE-2018-20997 unknown FIX debian debian 8y ago An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
CVE-2017-15412 critical 9.5 FIX arch arch slesdebian debian 9y ago Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2014-4914 critical 9.8 9.8 debian debian zend 9y ago The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVE-2015-7224 critical 9.8 9.8 FIX debian debian puppet 9y ago puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host…
CVE-2017-17821 critical 9.8 9.8 FIX debian debian apple 9y ago WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other im…
CVE-2017-15896 critical 9.1 9.1 FIX slesdebian debian nodejs 9y ago Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application dat…
CVE-2017-17499 critical 9.8 9.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
CVE-2017-17484 critical 9.8 9.8 FIX slesdebian debian icu-project 9y ago The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote a…
CVE-2017-17480 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu uclouvain 9y ago In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of serv…
CVE-2017-17479 critical 9.8 9.8 FIX slesdebian debian uclouvain 9y ago In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of servi…
CVE-2016-5713 critical 9.8 9.8 FIX debian debian puppet 9y ago Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to…
CVE-2017-17434 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also …
CVE-2016-1253 critical 9.8 9.8 FIX debian debian debian 9y ago The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell …
CVE-2017-8818 critical 9.8 9.8 FIX arch archdebian debian haxx 9y ago curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too litt…
CVE-2017-8817 critical 9.8 9.8 FIX arch arch slesdebian debian haxx 9y ago The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact v…
CVE-2017-8816 critical 9.8 9.8 FIX arch arch slesdebian debian haxx 9y ago The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application cr…
CVE-2017-14746 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
CVE-2017-16943 critical 9.8 9.8 FIX arch archdebian debian exim 9y ago The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BD…
CVE-2017-16931 critical 9.8 9.8 FIX slesdebian debian xmlsoft 9y ago parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.
CVE-2017-15088 critical 9.8 9.8 FIX arch arch slesdebian debian mit 9y ago plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause …
CVE-2017-16926 critical 9.8 9.8 FIX debian debian ohcount_project 9y ago Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for Ohcount processing) t…
CVE-2017-16613 critical 9.8 9.8 debian debian openstack 9y ago An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieve…
CVE-2017-16840 critical 9.8 9.8 FIX arch archdebian debian ffmpeg 9y ago The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related t…
CVE-2017-16896 critical 9.8 9.8 FIX debian debian tt-rss 9y ago A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
CVE-2017-16845 critical 10.0 10.0 FIX slesdebian debianubuntu ubuntu qemu 9y ago hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
CVE-2017-1000215 critical 9.8 9.8 FIX slesdebian debian xrootd 9y ago ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
CVE-2017-1000206 critical 9.8 9.8 FIX debian debian htslib 9y ago samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution
CVE-2017-16872 critical 9.8 9.8 debian debian teluu 9y ago An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overf…
CVE-2017-1000158 critical 9.8 9.8 FIX slesdebian debian python 9y ago CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code ex…
CVE-2017-1000232 critical 9.8 9.8 FIX slesdebian debian nlnetlabs 9y ago A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.
CVE-2017-1000231 critical 9.8 9.8 FIX slesdebian debian nlnetlabs 9y ago A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
CVE-2017-1000228 critical 9.8 9.8 FIX debian debian ejs 9y ago nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
CVE-2017-16844 critical 9.8 9.8 FIX slesdebian debian procmail 9y ago Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code…
CVE-2017-8807 critical 9.1 9.1 FIX debian debian varnish-cachevarnish_cache_project 9y ago vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a V…
CVE-2017-1000248 critical 9.8 9.8 FIX debian debian redis-store 9y ago Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
CVE-2017-8809 critical 9.8 9.8 FIX arch archdebian debian mediawiki 9y ago api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
CVE-2017-16820 critical 9.8 9.8 FIX debian debian collectd 9y ago The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other imp…
CVE-2015-7501 critical 9.8 9.8 FIX debian debian redhat 9y ago Deserialization of Untrusted Data in Apache commons collections
CVE-2017-2922 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while l…
CVE-2017-2921 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to …
CVE-2017-2894 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow…
CVE-2017-2892 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory…
CVE-2017-2891 critical 9.8 9.8 FIX debian debian cesanta 9y ago An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed poi…
CVE-2017-16548 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (…
CVE-2017-16510 critical 9.8 9.8 FIX debian debian wordpress 9y ago WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "d…
CVE-2017-1000121 critical 9.8 9.8 FIX debian debian webkitgtk 9y ago The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subse…
CVE-2017-1000257 critical 9.1 9.1 FIX slesarch archdebian debian haxx 9y ago An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer …
CVE-2013-4366 critical 9.8 9.8 FIX debian debian apache 9y ago Hostname verification in Apache HttpClient 4.3 was disabled by default
CVE-2017-15597 critical 9.1 9.1 FIX slesdebian debian 9y ago An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not mat…
CVE-2015-3249 critical 9.8 9.8 FIX debian debian apache 9y ago The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary …
CVE-2014-3624 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
CVE-2017-16228 critical 9.8 9.8 FIX slesdebian debian dulwich_project 9y ago Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017…
CVE-2017-15994 critical 9.8 9.8 FIX arch archdebian debian samba 9y ago rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has signi…
CVE-2017-16229 unknown FIX debian debian 9y ago In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse.
CVE-2014-3600 critical 9.8 9.8 FIX debian debian apache 9y ago Improper Restriction of XML External Entity Reference in Apache ActiveMQ
CVE-2012-4570 critical 9.8 9.8 FIX debian debian letodms_project 9y ago SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.