Search

Found 3,768 results in 1218ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-22049 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22045 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22036 low 3.7 3.7 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2023-22006 low 3.1 3.1 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2023-29405 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29404 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29403 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29402 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-20867 low 4.0 KEVFIX rhel rocky sles 3y ago VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the…
CVE-2016-9079 critical 10.0 KEVEXPFIX arch arch slesdebian debian 3y ago Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
CVE-2022-43552 low 2.5 FIX rheldebian debian sles 3y ago A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operat…
CVE-2022-36227 low 2.5 FIX rocky rhel sles 3y ago RHSA-2023:3018: libarchive security update (Low)
CVE-2022-35252 low 2.5 FIX rheldebian debian sles 3y ago When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. …
CVE-2022-28805 low 2.5 FIX rhel slesdebian debian 3y ago Low: lua security update
CVE-2022-1615 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:2987: samba security, bug fix, and enhancement update (Low)
CVE-2023-21968 low 3.7 3.7 FIX rhel rocky sles oraclenetapp 3y ago RHSA-2023:4103: java-1.8.0-ibm security update (Important)
CVE-2022-41862 low 2.5 FIX rhel rocky sles 3y ago RHSA-2023:7016: libpq security update (Low)
CVE-2023-28531 critical 9.8 9.8 FIX debian debian openbsd 3y ago ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
CVE-2022-45047 critical 9.8 9.8 FIX debian debian apache 4y ago Unsafe deserialization in Apache MINA SSHD
CVE-2022-2990 low 2.5 FIX rhel rocky sles 4y ago RHSA-2022:7822: container-tools:rhel8 security, bug fix, and enhancement update (Low)
CVE-2022-24736 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-24735 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-23645 low 2.5 FIX rhel rockydebian debian 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-2211 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-1122 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7645: openjpeg2 security update (Low)
CVE-2022-0897 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2021-46195 low 2.5 FIX rheldebian debian sles 4y ago Low: mingw-gcc security and bug fix update
CVE-2021-44269 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7558: wavpack security update (Low)
CVE-2021-3507 low 2.5 FIX rhel sles rocky 4y ago A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers fr…
CVE-2020-23903 low 2.5 FIX rhelarch arch sles 4y ago Low: speex security update
CVE-2022-39399 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2022:7012: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-21624 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-21619 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-3358 low 3.5 EXPFIX rhel slesdebian debian 4y ago Low: openssl security and bug fix update
CVE-2020-26269 critical 9.5 FIX arch archdebian debian 4y ago In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the direc…
CVE-2022-39269 critical 9.1 9.1 FIX debian debian teluu 4y ago PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SR…
CVE-2021-41556 critical 10.0 10.0 debian debianfedora fedora squirrel-lang 4y ago sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel …
CVE-2022-32224 critical 9.8 9.8 FIX rocky slesdebian debian activerecord_project 4y ago Active Record RCE bug with Serialized Columns
CVE-2022-34835 critical 9.8 9.8 FIX slesdebian debian denx 4y ago In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md …
CVE-2020-13950 low 2.5 FIX debian debianarch arch sles 4y ago Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, le…
CVE-2018-17480 critical 10.0 KEVFIX arch archdebian debian 4y ago Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple w…
CVE-2022-1802 critical 9.5 FIX arch arch rhel sles 4y ago If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged cont…
CVE-2022-1529 critical 9.5 FIX arch arch rhel sles 4y ago An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled Ja…
CVE-2020-22083 low 2.5 arch archdebian debian 4y ago ** DISPUTED ** jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and cl…
CVE-2019-5815 critical 9.5 FIX arch archdebian debian 4y ago Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
CVE-2019-13720 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11707 critical 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2011-4617 low 1.2 FIX debian debian python 4y ago virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.
CVE-2013-4278 low 3.5 FIX debian debian openstack 4y ago The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot…
CVE-2014-1948 low 2.6 FIX debian debian openstack 4y ago OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARN…
CVE-2014-0056 low 2.1 FIX ubuntu ubuntudebian debian openstack 4y ago The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants …
CVE-2013-4463 low 2.1 FIX debian debian openstack 4y ago OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumpti…
CVE-2013-4469 low 1.9 FIX debian debian openstack 4y ago OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (ho…
CVE-2014-1624 low 3.3 FIX slesdebian debian python 4y ago Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to …
CVE-2015-8914 critical 9.1 9.1 FIX slesdebian debian openstack 4y ago The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of s…
CVE-2014-1934 low 3.3 FIX debian debiansuse suse travis_shirk 4y ago tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.
CVE-2018-5158 critical 9.5 FIX arch archdebian debian 4y ago The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permis…
CVE-2017-3590 low 3.3 3.3 FIX debian debian oracle 4y ago Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows…
CVE-2017-1000116 critical 9.8 9.8 FIX arch arch slesdebian debian mercurial 4y ago Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVE-2017-17458 critical 9.8 9.8 FIX slesdebian debian mercurial 4y ago In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the rep…
CVE-2014-8991 low 2.1 FIX slesdebian debian pypa 4y ago pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
CVE-2013-1888 low 2.1 FIX fedora fedoradebian debian pypa 4y ago pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
CVE-2017-7550 critical 9.8 9.8 FIX debian debian sles rhel redhat 4y ago A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive infor…
CVE-2021-3981 low 2.5 FIX sles rockydebian debian 4y ago RHSA-2022:2110: grub2 security, bug fix, and enhancement update (Low)
CVE-2021-3634 low 2.5 FIX arch arch sles rocky 4y ago RHSA-2022:2031: libssh security, bug fix, and enhancement update (Low)
CVE-2021-3802 low 2.5 FIX sles rockydebian debian 4y ago RHSA-2022:1820: udisks2 security and bug fix update (Low)
CVE-2021-41229 low 2.5 FIX debian debianarch arch sles 4y ago RHSA-2022:2081: bluez security update (Low)
CVE-2021-23222 low 2.5 FIX arch arch sles rocky 4y ago RHSA-2022:1891: libpq security update (Low)
CVE-2020-17489 low 2.5 FIX slesdebian debian rocky 4y ago RHSA-2022:1814: gnome-shell security and bug fix update (Low)
CVE-2019-8506 low 5.0 KEVEXPFIX rockydebian debian rhel 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2010-0156 low 3.3 FIX debian debian puppet 4y ago Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or…
CVE-2021-41945 critical 9.5 FIX arch archdebian debian 4y ago Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
CVE-2017-9841 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by …
CVE-2020-7247 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
CVE-2021-29607 critical 9.5 FIX arch archdebian debian 4y ago TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) a…
CVE-2021-4091 low 2.5 FIX debian debian sles rocky 4y ago RHSA-2022:0889: 389-ds:1.4 security and bug fix update (Low)
CVE-2021-36368 low 3.7 3.7 FIX slesdebian debian openbsd 4y ago An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to…
CVE-2019-16928 critical 10.0 KEVFIX arch archdebian debian 4y ago Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CVE-2020-8562 low 2.2 2.2 FIX arch arch slesdebian debian kubernetes 4y ago As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Servi…
CVE-2021-44142 critical 9.5 FIX arch arch sles rocky 4y ago RHSA-2022:0332: samba security and bug fix update (Critical)
CVE-2022-23305 critical 9.8 9.8 FIX debian debian sles rocky apachenetappbroadcom 4y ago RHSA-2022:0290: parfait:0.5 security update (Important)
CVE-2019-10149 critical 10.0 KEVEXPFIX arch archdebian debian 5y ago A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2021-3930 low 2.5 FIX sles rockydebian debian 5y ago An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). …
CVE-2021-20257 low 2.5 FIX sles rockydebian debian 5y ago An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi…
CVE-2021-4102 critical 10.0 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2020-25717 critical 9.5 FIX arch arch sles rocky 5y ago RHSA-2022:0332: samba security and bug fix update (Critical)
CVE-2021-44228 critical 10.0 KEVEXPFIX arch archdebian debian sles 5y ago Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
CVE-2021-43527 critical 9.5 FIX arch arch sles rocky 5y ago NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatu…
CVE-2021-3572 low 2.5 FIX arch arch sles rocky 5y ago A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest…
CVE-2020-24370 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4510: lua security update (Low)
CVE-2021-20266 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4489: rpm security, bug fix, and enhancement update (Low)
CVE-2021-3200 low 2.5 FIX sles rockydebian debian 5y ago Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c…
CVE-2020-16135 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4387: libssh security update (Low)
CVE-2018-20673 low 2.5 debian debian sles rocky 5y ago RHSA-2021:4386: gcc security and bug fix update (Low)
CVE-2020-14155 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2019-20838 low 2.5 sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2020-18442 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4316: zziplib security update (Low)
CVE-2020-8037 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4236: tcpdump security and bug fix update (Low)
CVE-2020-36314 low 2.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2021-43566 low 2.5 FIX sles rockydebian debian 5y ago RHBA-2021:4438: samba bug fix and enhancement update (Low)