Search

Found 4,389 results in 185ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-46195 low 2.5 FIX rheldebian debian sles 4y ago Low: mingw-gcc security and bug fix update
CVE-2021-44269 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7558: wavpack security update (Low)
CVE-2021-3507 low 2.5 FIX rhel sles rocky 4y ago A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers fr…
CVE-2020-23903 low 2.5 FIX rhelarch arch sles 4y ago Low: speex security update
CVE-2022-39399 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2022:7012: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-21624 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-21619 low 3.7 3.7 FIX rhel sles rocky oraclenetappazul 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-3358 low 3.5 EXPFIX rhel slesdebian debian 4y ago Low: openssl security and bug fix update
CVE-2020-13950 low 2.5 FIX debian debianarch arch sles 4y ago Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, le…
CVE-2020-22083 low 2.5 arch archdebian debian 4y ago ** DISPUTED ** jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and cl…
CVE-2011-4617 low 1.2 FIX debian debian python 4y ago virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.
CVE-2013-4278 low 3.5 FIX debian debian openstack 4y ago The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot…
CVE-2014-1948 low 2.6 FIX debian debian openstack 4y ago OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARN…
CVE-2014-0056 low 2.1 FIX ubuntu ubuntudebian debian openstack 4y ago The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants …
CVE-2013-4463 low 2.1 FIX debian debian openstack 4y ago OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumpti…
CVE-2013-4469 low 1.9 FIX debian debian openstack 4y ago OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (ho…
CVE-2015-4053 low 2.1 ceph 4y ago The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.
CVE-2015-8034 low 3.3 3.3 sles saltstack 4y ago The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obtain sensitive information by reading the file.
CVE-2014-1624 low 3.3 FIX slesdebian debian python 4y ago Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to …
CVE-2014-1934 low 3.3 FIX debian debiansuse suse travis_shirk 4y ago tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.
CVE-2017-3590 low 3.3 3.3 FIX debian debian oracle 4y ago Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows…
CVE-2014-8991 low 2.1 FIX slesdebian debian pypa 4y ago pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
CVE-2013-1888 low 2.1 FIX fedora fedoradebian debian pypa 4y ago pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
CVE-2022-24101 low 3.3 3.3 4y ago Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensit…
CVE-2021-3981 low 2.5 FIX sles rockydebian debian 4y ago RHSA-2022:2110: grub2 security, bug fix, and enhancement update (Low)
CVE-2021-3634 low 2.5 FIX arch arch sles rocky 4y ago RHSA-2022:2031: libssh security, bug fix, and enhancement update (Low)
CVE-2021-3802 low 2.5 FIX sles rockydebian debian 4y ago RHSA-2022:1820: udisks2 security and bug fix update (Low)
CVE-2021-41229 low 2.5 FIX debian debianarch arch sles 4y ago RHSA-2022:2081: bluez security update (Low)
CVE-2021-23222 low 2.5 FIX arch arch sles rocky 4y ago RHSA-2022:1891: libpq security update (Low)
CVE-2020-17489 low 2.5 FIX slesdebian debian rocky 4y ago RHSA-2022:1814: gnome-shell security and bug fix update (Low)
CVE-2019-8506 low 5.0 KEVEXPFIX rockydebian debian rhel 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2010-0156 low 3.3 FIX debian debian puppet 4y ago Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or…
CVE-2021-3461 low 2.5 FIX arch arch 4y ago Keycloak insufficient session expiration
CVE-2021-4091 low 2.5 FIX debian debian sles rocky 4y ago RHSA-2022:0889: 389-ds:1.4 security and bug fix update (Low)
CVE-2021-36368 low 3.7 3.7 FIX slesdebian debian openbsd 4y ago An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to…
CVE-2014-0177 low 3.6 github 4y ago Hub Package Arbitrary File Overwrite
CVE-2020-8562 low 2.2 2.2 FIX arch arch slesdebian debian kubernetes 4y ago As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Servi…
CVE-2021-3930 low 2.5 FIX sles rockydebian debian 5y ago An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). …
CVE-2021-20257 low 2.5 FIX sles rockydebian debian 5y ago An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi…
CVE-2021-43668 low 2.5 arch arch 5y ago Denial of Service in Go-Ethereum
CVE-2021-3572 low 2.5 FIX arch arch sles rocky 5y ago A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest…
CVE-2020-24370 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4510: lua security update (Low)
CVE-2021-20266 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4489: rpm security, bug fix, and enhancement update (Low)
CVE-2021-3200 low 2.5 FIX sles rockydebian debian 5y ago Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c…
CVE-2020-16135 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4387: libssh security update (Low)
CVE-2018-20673 low 2.5 debian debian sles rocky 5y ago RHSA-2021:4386: gcc security and bug fix update (Low)
CVE-2020-14155 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2019-20838 low 2.5 sles rockydebian debian 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2020-18442 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4316: zziplib security update (Low)
CVE-2020-8037 low 2.5 FIX sles rockydebian debian 5y ago RHSA-2021:4236: tcpdump security and bug fix update (Low)
CVE-2020-36314 low 2.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2021-43566 low 2.5 FIX sles rockydebian debian 5y ago RHBA-2021:4438: samba bug fix and enhancement update (Low)
CVE-2021-20269 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:4404: kexec-tools security, bug fix, and enhancement update (Low)
CVE-2020-13987 low 2.5 FIX slesdebian debian rhel 5y ago RHBA-2021:4446: iscsi-initiator-utils bug fix and enhancement update (Low)
CVE-2021-3828 low 2.5 FIX arch archdebian debian 5y ago nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-37860 low 2.5 FIX arch arch 5y ago Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server
CVE-2021-25740 low 3.1 3.1 FIX arch arch slesdebian debian kubernetes 5y ago A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
CVE-2021-40839 low 2.5 FIX arch archdebian debian 5y ago The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
CVE-2021-25737 low 2.5 FIX arch arch slesdebian debian 5y ago A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or …
CVE-2021-23437 low 2.5 FIX arch arch slesdebian debian 5y ago The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
CVE-2021-22918 low 2.5 FIX arch arch rockydebian debian 5y ago Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whethe…
CVE-2021-3652 low 2.5 FIX debian debianarch arch sles 5y ago RHSA-2021:3079: 389-ds:1.4 security and bug fix update (Low)
CVE-2021-29063 low 2.5 FIX arch archdebian debian 5y ago A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 when the mpmathify function is called.
CVE-2021-32813 low 2.5 FIX arch arch 5y ago Header dropping in traefik in github.com/traefik/traefik
CVE-2021-36374 low 2.5 FIX debian debianarch arch sles 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-36373 low 2.5 FIX debian debianarch arch sles 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant
CVE-2021-21303 low 2.5 FIX arch arch 5y ago insufficient validation in helm
CVE-2021-29957 low 2.5 FIX arch arch sles rocky 5y ago multiple issues in thunderbird
CVE-2021-29956 low 2.5 FIX arch arch sles rocky 5y ago multiple issues in thunderbird
CVE-2021-31542 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
CVE-2021-26813 low 2.5 FIX arch archdebian debian 5y ago markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or de…
CVE-2021-20201 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:1924: spice security update (Low)
CVE-2019-17402 low 2.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1758: exiv2 security, bug fix, and enhancement update (Low)
CVE-2020-16117 low 2.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1752: evolution security, bug fix, and enhancement update (Low)
CVE-2019-2708 low 2.5 sles rocky rhel 5y ago RHSA-2021:1675: libdb security update (Low)
CVE-2021-23240 low 2.5 FIX arch arch sles rocky 5y ago selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary …
CVE-2021-23239 low 2.5 FIX arch arch sles rocky 5y ago The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled…
CVE-2020-36318 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:1935: rust-toolset:rhel8 security, bug fix, and enhancement update (Low)
CVE-2020-36317 low 2.5 FIX arch arch sles rocky 5y ago RHSA-2021:1935: rust-toolset:rhel8 security, bug fix, and enhancement update (Low)
CVE-2019-18276 low 2.5 FIX debian debian sles rhel 5y ago RHSA-2021:1679: bash security and bug fix update (Low)
CVE-2021-32618 low 2.5 FIX arch arch sles 5y ago The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of…
CVE-2020-29651 low 2.5 FIX arch arch slesdebian debian 5y ago A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying …
CVE-2021-27919 low 2.5 FIX arch arch slesdebian debian 5y ago archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any fi…
CVE-2021-28658 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were no…
CVE-2021-3281 low 2.5 FIX arch arch slesdebian debian 5y ago In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal …
CVE-2021-21330 low 2.5 FIX arch arch slesdebian debian 5y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based…
CVE-2021-21236 low 2.5 FIX debian debianarch arch 6y ago CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When process…
CVE-2020-3898 low 2.5 FIX debian debian sles rocky 6y ago RHSA-2020:4469: cups security and bug fix update (Low)
CVE-2020-11736 low 2.5 FIX arch arch slesdebian debian 6y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2019-20386 low 2.5 FIX slesdebian debian rhel 6y ago An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
CVE-2019-17450 low 2.5 FIX debian debian sles rhel 6y ago RHSA-2020:4465: binutils security update (Low)
CVE-2019-16167 low 2.5 FIX sles rockydebian debian 6y ago RHSA-2020:4638: sysstat security update (Low)
CVE-2019-1551 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4514: openssl security, bug fix, and enhancement update (Low)
CVE-2020-14928 low 2.5 FIX slesdebian debian rocky 6y ago RHSA-2020:4649: evolution security and bug fix update (Low)
CVE-2019-14494 low 2.5 FIX slesdebian debian rhel 6y ago An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
CVE-2020-12803 low 2.5 FIX arch arch sles rocky 6y ago ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable f…
CVE-2020-12802 low 2.5 FIX arch arch sles rocky 6y ago LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
CVE-2019-15165 low 2.5 FIX slesdebian debian rhel 6y ago RHSA-2020:4547: libpcap security, bug fix, and enhancement update (Low)
CVE-2020-10759 low 2.5 FIX arch arch slesdebian debian 6y ago A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practi…
CVE-2018-10896 low 2.5 rhel 6y ago RHSA-2020:3050: cloud-init security, bug fix, and enhancement update (Low)