Search

Found 5,526 results in 2468ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-3287 medium 5.5 FIX rhel rocky sles 3y ago When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read …
CVE-2022-32323 medium 5.5 rhel 3y ago RHSA-2023:3067: autotrace security update (Moderate)
CVE-2022-3204 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: unbound security update
CVE-2022-3190 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: wireshark security and bug fix update
CVE-2022-3165 medium 5.5 FIX rocky rhel sles 3y ago An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending…
CVE-2022-3094 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:7177: bind security update (Moderate)
CVE-2022-30789 medium 5.5 FIX arch arch rocky rhel 3y ago RHSA-2023:2757: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2022-30788 medium 5.5 FIX arch arch rocky rhel 3y ago RHSA-2023:2757: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2022-30786 medium 5.5 FIX arch arch rocky rhel 3y ago RHSA-2023:2757: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2022-30784 medium 5.5 FIX arch arch rocky rhel 3y ago RHSA-2023:2757: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2022-2929 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:3000: dhcp security and bug fix update (Moderate)
CVE-2022-2928 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:3000: dhcp security and bug fix update (Moderate)
CVE-2022-29187 medium 5.5 FIX arch arch rhel sles 3y ago RHSA-2023:2859: git security and bug fix update (Moderate)
CVE-2022-28805 low 2.5 FIX rhel slesdebian debian 3y ago Low: lua security update
CVE-2022-2795 medium 5.5 FIX arch arch rheldebian debian 3y ago RHSA-2023:3002: bind security and bug fix update (Moderate)
CVE-2022-24765 medium 5.5 FIX rhelarch arch sles 3y ago RHSA-2023:2859: git security and bug fix update (Moderate)
CVE-2022-2393 medium 5.5 rheldebian debian 3y ago Moderate: pki-core security, bug fix, and enhancement update
CVE-2022-2122 medium 5.5 FIX rheldebian debian sles 3y ago DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending…
CVE-2022-1925 medium 5.5 FIX rheldebian debian sles 3y ago DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to…
CVE-2022-1924 medium 5.5 FIX rhel slesdebian debian 3y ago DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrit…
CVE-2022-1923 medium 5.5 FIX rhel slesdebian debian 3y ago DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwr…
CVE-2022-1922 medium 5.5 FIX rhel slesdebian debian 3y ago DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a h…
CVE-2022-1921 medium 5.5 FIX rheldebian debian sles 3y ago Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
CVE-2022-1920 medium 5.5 FIX rheldebian debian sles 3y ago Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through hea…
CVE-2022-1615 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:2987: samba security, bug fix, and enhancement update (Low)
CVE-2021-46829 medium 5.5 FIX arch arch rhel sles 3y ago Moderate: gdk-pixbuf2 security update
CVE-2021-46790 medium 5.5 FIX rocky rhel sles 3y ago RHSA-2023:2757: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2021-44648 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: gdk-pixbuf2 security update
CVE-2020-36518 medium 5.5 FIX rhel slesdebian debian 3y ago jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
CVE-2020-17049 medium 5.5 rhel sles rocky 3y ago RHSA-2024:0143: idm:DL1 security update (Moderate)
CVE-2022-37454 medium 5.5 FIX rocky rhel sles 3y ago The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic…
CVE-2023-21968 low 3.7 3.7 FIX rhel rocky sles oraclenetapp 3y ago RHSA-2023:4103: java-1.8.0-ibm security update (Important)
CVE-2023-25725 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: haproxy security update
CVE-2023-23916 medium 5.5 FIX rheldebian debian rocky 3y ago An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed mult…
CVE-2023-0056 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: haproxy security update
CVE-2022-41862 low 2.5 FIX rhel rocky sles 3y ago RHSA-2023:7016: libpq security update (Low)
CVE-2022-2625 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:1576: postgresql:13 security update (Moderate)
CVE-2022-4899 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2024:0894: mysql:8.0 security update (Moderate)
CVE-2023-28756 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2024:3500: ruby:3.0 security update (Moderate)
CVE-2023-28755 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2024:4499: ruby security update (Moderate)
CVE-2023-0778 medium 5.5 FIX rocky slesdebian debian 3y ago RHSA-2023:2802: container-tools:4.0 security and bug fix update (Moderate)
CVE-2023-27539 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:3082: pcs security and bug fix update (Moderate)
CVE-2023-0361 medium 5.5 FIX rhel rocky sles 3y ago Moderate: gnutls security and bug fix update
CVE-2021-46822 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libjpeg-turbo security update
CVE-2023-27530 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:3082: pcs security and bug fix update (Moderate)
CVE-2022-48303 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:0842: tar security update (Moderate)
CVE-2022-47024 medium 5.5 FIX arch arch rhel sles 3y ago A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impa…
CVE-2022-45873 medium 5.5 FIX rhel sles rocky 3y ago systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation m…
CVE-2022-45061 medium 5.5 FIX rocky rhel sles 3y ago Moderate: python3.9 security update
CVE-2022-4415 medium 5.5 FIX rhel rocky sles 3y ago A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
CVE-2022-40897 medium 5.5 FIX rhel rocky sles google 3y ago RHSA-2024:2987: python27:2.7 security update (Moderate)
CVE-2022-37436 medium 5.5 FIX arch archdebian debian rhel 3y ago Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers…
CVE-2022-36760 medium 5.5 FIX arch archdebian debian rhel 3y ago Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards reque…
CVE-2022-31631 medium 5.5 FIX rocky rhel sles 3y ago RHSA-2023:2903: php:7.4 security update (Moderate)
CVE-2022-31630 medium 5.5 FIX rocky rhel sles 3y ago RHSA-2023:2903: php:7.4 security update (Moderate)
CVE-2022-31629 medium 5.5 FIX rocky rheldebian debian 3y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2022-31628 medium 5.5 FIX rocky rhel sles 3y ago RHSA-2023:2903: php:7.4 security update (Moderate)
CVE-2021-44964 medium 5.5 FIX rhel sles rocky 3y ago Moderate: lua security update
CVE-2021-43519 medium 5.5 FIX rhelarch arch sles 3y ago Moderate: lua security update
CVE-2006-20001 medium 5.5 FIX slesarch archdebian debian 3y ago A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. …
CVE-2022-4900 medium 5.5 FIX slesdebian debian rhel 3y ago RHSA-2023:0848: php:8.0 security update (Moderate)
CVE-2023-0494 medium 5.5 FIX rhel rocky sles 3y ago A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write …
CVE-2023-0401 medium 5.5 FIX rhel sles rocky 3y ago Moderate: openssl security and bug fix update
CVE-2023-0217 medium 5.5 FIX rhel sles rocky 3y ago Moderate: openssl security and bug fix update
CVE-2023-0216 medium 5.5 FIX rhel sles rocky 3y ago Moderate: openssl security and bug fix update
CVE-2022-4203 medium 5.5 FIX rhel sles rocky 3y ago Moderate: openssl security and bug fix update
CVE-2023-21830 medium 5.3 5.3 FIX rhel rocky sles 3y ago RHSA-2023:0208: java-1.8.0-openjdk security and bug fix update (Moderate)
CVE-2023-21843 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:0208: java-1.8.0-openjdk security and bug fix update (Moderate)
CVE-2023-21835 medium 5.3 5.3 FIX rhel rocky sles 3y ago RHSA-2023:0200: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-50054 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: iavf: Fix NULL pointer dereference in iavf_get_link_ksettings Fix possible NULL pointer dereference, due to freeing of adapter->v…
CVE-2022-50053 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: iavf: Fix reset error handling Do not call iavf_close in iavf_reset_task error handling. Doing so can lead to double call of napi…
CVE-2022-43680 medium 5.5 FIX rheldebian debian rocky 3y ago RHSA-2023:0103: expat security update (Moderate)
CVE-2022-42012 medium 5.5 FIX arch arch rheldebian debian 3y ago An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to cras…
CVE-2022-42011 medium 5.5 FIX arch arch rheldebian debian 3y ago An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to cras…
CVE-2022-42010 medium 5.5 FIX arch arch rheldebian debian 3y ago An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to cras…
CVE-2022-41717 medium 5.5 FIX rocky rhel sles 3y ago Moderate: podman security and bug fix update
CVE-2022-41715 medium 5.5 FIX rhelalmalinux almalinux rocky 3y ago Moderate: container-tools:rhel8 security update
CVE-2022-40304 medium 5.5 FIX rhel rocky sles 3y ago An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can b…
CVE-2022-40303 medium 5.5 FIX rhel rocky sles 3y ago An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an a…
CVE-2022-3821 medium 5.5 FIX rhel sles rocky 3y ago An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format…
CVE-2022-3715 medium 5.5 FIX rheldebian debian rocky 3y ago Moderate: bash security update
CVE-2022-32221 medium 5.5 FIX rheldebian debian sles 3y ago When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same han…
CVE-2022-3140 medium 5.5 FIX arch arch rhel rocky 3y ago LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In th…
CVE-2022-31197 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: postgresql-jdbc security update
CVE-2022-2953 medium 5.5 FIX arch arch rhelalmalinux almalinux 3y ago RHSA-2023:0095: libtiff security update (Moderate)
CVE-2022-2880 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2022-2879 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2022-27664 medium 5.5 FIX rocky rhel sles 3y ago Moderate: grafana-pcp security and enhancement update
CVE-2022-26307 medium 5.5 FIX arch arch rhel rocky 3y ago LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in Lib…
CVE-2022-26306 medium 5.5 FIX arch arch rhel rocky 3y ago LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in Lib…
CVE-2022-26305 medium 5.5 FIX arch arch rhel rocky 3y ago An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of th…
CVE-2022-2521 medium 5.5 FIX arch arch rhelalmalinux almalinux 3y ago RHSA-2023:0095: libtiff security update (Moderate)
CVE-2022-2520 medium 5.5 FIX arch arch rhelalmalinux almalinux 3y ago RHSA-2023:0095: libtiff security update (Moderate)
CVE-2022-2519 medium 5.5 FIX arch arch rhelalmalinux almalinux 3y ago RHSA-2023:0095: libtiff security update (Moderate)
CVE-2022-2058 medium 5.5 FIX arch arch rhelalmalinux almalinux 3y ago RHSA-2023:0095: libtiff security update (Moderate)
CVE-2022-2057 medium 5.5 FIX arch arch rhel rocky 3y ago RHSA-2023:0095: libtiff security update (Moderate)
CVE-2022-2056 medium 5.5 FIX arch arch rhel rocky 3y ago RHSA-2023:0095: libtiff security update (Moderate)
CVE-2021-46848 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:0116: libtasn1 security update (Moderate)
CVE-2021-44906 medium 5.5 FIX rhel sles rocky 3y ago RHSA-2023:0050: nodejs:14 security, bug fix, and enhancement update (Moderate)
CVE-2019-25058 medium 5.5 FIX rhel sles rocky 3y ago RHSA-2023:0087: usbguard security update (Moderate)