Search

Found 1,349 results in 225ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-8562 low 2.2 2.2 FIX arch arch slesdebian debian kubernetes 4y ago As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Servi…
CVE-2021-3930 low 2.5 FIX sles rockydebian debian 5y ago An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). …
CVE-2021-20257 low 2.5 FIX sles rockydebian debian 5y ago An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi…
CVE-2021-3572 low 2.5 FIX arch arch sles rocky 5y ago A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest…
CVE-2020-24370 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4510: lua security update (Low)
CVE-2021-20266 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4489: rpm security, bug fix, and enhancement update (Low)
CVE-2021-3200 low 2.5 FIX sles rockydebian debian 5y ago Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c…
CVE-2020-16135 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4387: libssh security update (Low)
CVE-2018-20673 low 2.5 debian debian sles rocky 5y ago RHSA-2021:4386: gcc security and bug fix update (Low)
CVE-2020-14155 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2019-20838 low 2.5 sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2020-18442 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4316: zziplib security update (Low)
CVE-2020-8037 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4236: tcpdump security and bug fix update (Low)
CVE-2020-36314 low 2.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2021-43566 low 2.5 FIX sles rockydebian debian 5y ago RHBA-2021:4438: samba bug fix and enhancement update (Low)
CVE-2021-20269 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:4404: kexec-tools security, bug fix, and enhancement update (Low)
CVE-2020-13987 low 2.5 FIX slesdebian debian rhel 5y ago RHBA-2021:4446: iscsi-initiator-utils bug fix and enhancement update (Low)
CVE-2021-3828 low 2.5 FIX arch archdebian debian 5y ago nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-25740 low 3.1 3.1 FIX arch arch slesdebian debian kubernetes 5y ago A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
CVE-2021-40839 low 2.5 FIX arch archdebian debian 5y ago The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
CVE-2021-25737 low 2.5 FIX arch arch slesdebian debian 5y ago A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or …
CVE-2021-23437 low 2.5 FIX arch arch slesdebian debian 5y ago The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
CVE-2021-22918 low 2.5 FIX arch arch rockydebian debian 5y ago Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whethe…
CVE-2021-3652 low 2.5 FIX debian debianarch arch sles 5y ago RHSA-2021:3079: 389-ds:1.4 security and bug fix update (Low)
CVE-2021-29063 low 2.5 FIX arch archdebian debian 5y ago A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 when the mpmathify function is called.
CVE-2021-36374 low 2.5 FIX debian debianarch arch sles 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-36373 low 2.5 FIX debian debianarch arch sles 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-29957 low 2.5 FIX arch arch sles rocky 5y ago multiple issues in thunderbird
CVE-2021-29956 low 2.5 FIX arch arch sles rocky 5y ago multiple issues in thunderbird
CVE-2021-31542 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
CVE-2021-26813 low 2.5 FIX arch archdebian debian 5y ago markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or de…
CVE-2021-20201 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:1924: spice security update (Low)
CVE-2019-17402 low 2.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1758: exiv2 security, bug fix, and enhancement update (Low)
CVE-2020-16117 low 2.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1752: evolution security, bug fix, and enhancement update (Low)
CVE-2021-23240 low 2.5 FIX arch arch sles rocky 5y ago selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary …
CVE-2021-23239 low 2.5 FIX arch arch sles rocky 5y ago The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled…
CVE-2020-36318 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:1935: rust-toolset:rhel8 security, bug fix, and enhancement update (Low)
CVE-2020-36317 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:1935: rust-toolset:rhel8 security, bug fix, and enhancement update (Low)
CVE-2019-18276 low 2.5 FIX debian debian sles rhel 5y ago RHSA-2021:1679: bash security and bug fix update (Low)
CVE-2020-29651 low 2.5 FIX arch arch slesdebian debian 5y ago A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying …
CVE-2021-27919 low 2.5 FIX arch arch slesdebian debian 5y ago archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any fi…
CVE-2021-28658 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were no…
CVE-2021-3281 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal …
CVE-2021-21330 low 2.5 FIX arch arch slesdebian debian 5y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based…
CVE-2021-21236 low 2.5 FIX debian debianarch arch 6y ago CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When process…
CVE-2020-3898 low 2.5 FIX debian debian sles rocky 6y ago RHSA-2020:4469: cups security and bug fix update (Low)
CVE-2020-11736 low 2.5 FIX arch arch slesdebian debian 6y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2019-20386 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4553: systemd security, bug fix, and enhancement update (Low)
CVE-2019-17450 low 2.5 FIX debian debian sles rhel 6y ago RHSA-2020:4465: binutils security update (Low)
CVE-2019-16167 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:4638: sysstat security update (Low)
CVE-2019-1551 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4514: openssl security, bug fix, and enhancement update (Low)
CVE-2020-14928 low 2.5 FIX slesdebian debian rocky 6y ago RHSA-2020:4649: evolution security and bug fix update (Low)
CVE-2019-14494 low 2.5 FIX slesdebian debian rhel 6y ago An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
CVE-2020-12803 low 2.5 FIX arch arch sles rocky 6y ago ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable f…
CVE-2020-12802 low 2.5 FIX arch arch sles rocky 6y ago LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
CVE-2019-15165 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4547: libpcap security, bug fix, and enhancement update (Low)
CVE-2020-10759 low 2.5 FIX arch arch slesdebian debian 6y ago A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practi…
CVE-2020-9488 low 3.7 3.7 FIX debian debian sles oracleapacheqos 6y ago Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log mess…
CVE-2020-11078 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4605: resource-agents security and bug fix update (Low)
CVE-2020-11054 low 2.5 FIX arch archdebian debian 6y ago In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (col…
CVE-2019-1010305 low 2.5 FIX slesdebian debian rocky 6y ago RHSA-2020:1686: libmspack security and bug fix update (Low)
CVE-2019-13045 low 2.5 FIX arch archdebian debian rocky 6y ago RHSA-2020:1616: irssi security update (Low)
CVE-2019-11498 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010319 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010317 low 2.5 FIX rockydebian debian rhel 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010315 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2018-19841 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2018-19840 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-8696 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:1765: cups security and bug fix update (Low)
CVE-2019-8675 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:1765: cups security and bug fix update (Low)
CVE-2019-19126 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:1828: glibc security, bug fix, and enhancement update (Low)
CVE-2019-17451 low 2.5 FIX debian debian sles rhel 6y ago RHSA-2020:1797: binutils security and bug fix update (Low)
CVE-2019-14834 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:1715: dnsmasq security, bug fix, and enhancement update (Low)
CVE-2019-13232 low 2.5 FIX arch arch slesdebian debian 6y ago RHSA-2020:1787: unzip security update (Low)
CVE-2019-1010204 low 2.5 FIX debian debian sles rhel 6y ago RHSA-2020:1797: binutils security and bug fix update (Low)
CVE-2018-19519 low 2.5 slesdebian debian rhel 6y ago RHSA-2020:1604: tcpdump security update (Low)
CVE-2018-10910 low 2.5 FIX debian debian sles rhel 6y ago RHSA-2020:1912: bluez security update (Low)
CVE-2019-19118 low 2.5 FIX arch archdebian debian 7y ago Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but ed…
CVE-2018-10393 low 2.5 FIX slesdebian debian rocky 7y ago RHSA-2019:3703: libvorbis security update (Low)
CVE-2018-10392 low 2.5 FIX slesdebian debian rocky 7y ago RHSA-2019:3703: libvorbis security update (Low)
CVE-2018-18751 low 2.5 FIX arch arch slesdebian debian 7y ago RHSA-2019:3643: gettext security update (Low)
CVE-2019-8768 low 2.5 FIX sles rockydebian debian 7y ago "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing h…
CVE-2019-8735 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processin…
CVE-2019-8726 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processin…
CVE-2019-8690 low 3.5 EXPFIX sles rockydebian debian 7y ago A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTun…
CVE-2019-8689 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8687 low 2.5 FIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8686 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8681 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8679 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8677 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8676 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8673 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8672 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8671 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8666 low 2.5 FIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8623 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8622 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8619 low 2.5 FIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for …
CVE-2019-8615 low 2.5 FIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for …