| Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli |
Insufficient Session Expiration |
saurabhb |
Low |
2025-05-29 |
| Apache Airflow Sql injection by authenticated user |
SQL Injection |
nxczje |
Low |
2025-05-27 |
| [SECURITY] CVE-2024-50379 Apache Tomcat - RCE via write-enabled default servlet |
Code Injection |
nacl_123 |
High |
2025-05-27 |
| TLS client authentication can be bypassed due to ticket resumption |
Improper Authentication - Generic |
snhebrok |
Medium |
2025-05-27 |
| CVE-2024-56374: Denial-of-service vulnerability in IPv6 validation |
None supplied |
sav_ |
Medium |
2025-05-27 |
| [CVE-2025-27220] ReDoS in CGI::Util#escapeElement |
Uncontrolled Resource Consumption |
svalkanov |
High |
2025-04-30 |
| Possible Sensitive Session Information Leak in Active Storage |
Information Disclosure |
tyage |
High |
2025-04-27 |
| CVE-2024-43398: DoS vulnerability in REXML |
Uncontrolled Resource Consumption |
l33thaxor |
Low |
2025-04-27 |
| Denial of Service by memory exhaustion in net/imap |
Allocation of Resources Without Limits or Throttling |
masamune_ |
Medium |
2025-04-27 |
| CVE-2025-24813: Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet |
Deserialization of Untrusted Data |
sw0rd1ight |
High |
2025-04-27 |
| [CVE-2025-27219] Denial of Service in CGI::Cookie.parse |
Uncontrolled Resource Consumption |
lio346 |
Medium |
2025-04-27 |
| CVE-2025-0725: Heap overflow in curl with Content-Encoding gzip and old libz versions |
Heap Overflow |
z2_ |
Low |
2025-04-27 |
| Possible DoS by memory exhaustion in net/imap |
Uncontrolled Resource Consumption |
manun |
Medium |
2025-04-27 |
| Deadlock in x86 HVM standard VGA handling |
Improper Input Validation |
stonksy |
Medium |
2025-03-07 |
| Possible ReDoS vulnerability in query parameter filtering in Action Dispatch |
Uncontrolled Resource Consumption |
scyoon |
Medium |
2025-03-07 |
| CVE-2024-53908: Django Potential SQL injection in `HasKey(lhs, rhs)` on Oracle |
SQL Injection |
scyoon |
High |
2025-02-07 |
| CVE-2024-56374 Potential denial-of-service in IPv6 validation |
Allocation of Resources Without Limits or Throttling |
0xsaravana |
Medium |
2025-02-06 |
| [CVE-2024-54133] Possible Content Security Policy bypass in Action Dispatch |
Cross-site Scripting (XSS) - Generic |
ryotak |
Low |
2025-02-06 |
| ActionView sanitize helper bypass with 'style' and 'svg' tags |
Cross-site Scripting (XSS) - Generic |
taise |
Medium |
2025-02-06 |
| ActionView sanitize helper bypass with noscript |
Cross-site Scripting (XSS) - Generic |
taise |
Medium |
2025-02-06 |
| ActionView sanitize helper bypass with style |
Cross-site Scripting (XSS) - Generic |
mokusou |
Medium |
2025-02-06 |
| ActionView sanitize helper bypass with style and math |
None supplied |
mokusou |
Medium |
2025-02-06 |
| #2931639 ActionView sanitize helper bypass with math-related tags |
Cross-site Scripting (XSS) - Generic |
mokusou |
Medium |
2025-02-06 |
| CVE-2024-45230 - Potential denial-of-service in django.utils.html.urlize() (Another pattern) |
Allocation of Resources Without Limits or Throttling |
mprogrammer |
Medium |
2025-02-05 |
| CVE-2022-40604: Apache Airflow: Format String Vulnerability |
Use of Externally-Controlled Format String |
leixiao |
Critical |
2025-01-18 |
| netrc and redirect credential leak |
Information Disclosure |
nyymi |
Low |
2025-01-15 |
| Apache Airflow: Sensitive Information Exposure in DAG Run Logs |
Information Disclosure |
saurabhb |
Medium |
2024-12-30 |
| Secrets not masked in UI when sensitive variables are set via Airflow cli |
Information Disclosure |
saurabhb |
Low |
2024-12-30 |
| CVE-2024-45498: Apache Airflow Command injection in read_dataset_event_from_classic DAG |
None supplied |
nhienit2010 |
Low |
2024-12-07 |
| CVE-2024-41990: Potential denial-of-service in django.utils.html.urlize() |
Allocation of Resources Without Limits or Throttling |
mprogrammer |
Medium |
2024-11-30 |
| CVE-2024-49761: ReDoS vulnerability in REXML |
Uncontrolled Resource Consumption |
manun |
Medium |
2024-11-30 |
| [CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text |
Uncontrolled Resource Consumption |
ooooooo_q |
Low |
2024-11-28 |
| `std::process::Command` batch files argument escaping could be bypassed with trailing whitespace or periods |
None supplied |
4xpl0r3r |
Low |
2024-11-22 |
| ReDoS Vulnerability in HTTP Accept Headers Parsing |
None supplied |
dwisiswant0 |
Medium |
2024-10-30 |
| fs.fchown/fchmod bypasses permission model |
Insecure Direct Object Reference (IDOR) |
4xpl0r3r |
Low |
2024-10-16 |
| Possible DoS Vulnerability with Range Header in Rack |
None supplied |
ooooooo_q |
High |
2024-09-25 |
| Possible XSS Vulnerability in Action Controller |
Cross-site Scripting (XSS) - Generic |
ooooooo_q |
Low |
2024-09-25 |
| CVE-2024-41989: Denial-Of-Service vulnerability in the floatformat template filter when input string contains a big exponent in scientific notation |
Uncontrolled Resource Consumption |
l33thaxor |
Medium |
2024-09-22 |
| curl: stack-buffer overread during punycode conversions |
Buffer Over-read |
z2_ |
Low |
2024-09-22 |
| Unbounded memory growth with session handling in TLSv1.3 |
Allocation of Resources Without Limits or Throttling |
manishpatidar |
Low |
2024-09-22 |
| CVE-2024-41937: Apache Airflow: Stored XSS Vulnerability on provider link |
Cross-site Scripting (XSS) - Stored |
sw0rd1ight |
Low |
2024-09-07 |
| CVE-2024-7347: Buffer overread in the ngx_http_mp4_module |
Buffer Over-read |
noentry |
Medium |
2024-08-27 |
| important: Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows (CVE-2024-40898) |
None supplied |
xi4o7unj1e |
High |
2024-08-27 |
| CVE-2024-42005: Potential SQL injection in QuerySet.values() and values_list() |
None supplied |
eyalsec |
High |
2024-08-24 |
| [CVE-2024-35176] DoS vulnerability in REXML |
Allocation of Resources Without Limits or Throttling |
mprogrammer |
Medium |
2024-08-23 |
| CVE-2024-38875: Denial-Of-Service through uncontrolled resource consumption caused by poor time complexity of strip_punctuation . |
Uncontrolled Resource Consumption |
l33thaxor |
Medium |
2024-08-23 |
| libcurl: freeing stack buffer during x509 certificate parsing |
Memory Corruption - Generic |
z2_ |
Medium |
2024-08-23 |
| moderate: Apache HTTP Server: mod_rewrite proxy handler substitution (CVE-2024-39573) CWE-20 Improper Input Validation |
Improper Input Validation |
orange |
Medium |
2024-08-12 |
| important: Apache HTTP Server weakness with encoded question marks in backreferences (CVE-2024-38474) |
Improper Input Validation |
orange |
High |
2024-07-13 |
| important: Apache HTTP Server on WIndows UNC SSRF (CVE-2024-38472) |
Server-Side Request Forgery (SSRF) |
orange |
High |
2024-07-13 |
| important: Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. (CVE-2024-38475) |
Improper Input Validation |
orange |
High |
2024-07-13 |
| important: Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect (CVE-2024-38476) |
Inclusion of Functionality from Untrusted Control Sphere |
orange |
High |
2024-07-13 |
| important: Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request (CVE-2024-38477) |
NULL Pointer Dereference |
orange |
High |
2024-07-13 |
| moderate: Apache HTTP Server: HTTP response splitting (CVE-2023-38709) |
HTTP Response Splitting |
orange |
Medium |
2024-07-13 |
| moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473) |
Improper Input Validation |
orange |
Medium |
2024-07-13 |
| CVE-2024-3416: MTU of 4096 or greater without fragmentation may cause NGINX worker processes to leak previously freed memory |
Information Disclosure |
noentry |
Medium |
2024-07-12 |
| CVE-2024-34750 Apache Tomcat DoS vulnerability in HTTP/2 connector |
Uncontrolled Resource Consumption |
devme4f |
High |
2024-07-05 |
| CVE-2024-32760 in nginx |
None supplied |
noentry |
Medium |
2024-07-01 |
| CVE-2024-31079 in nginx |
Stack Overflow |
noentry |
Medium |
2024-07-01 |
| CVE-2024-35200 in nginx |
NULL Pointer Dereference |
noentry |
Medium |
2024-07-01 |
| [CVE-2024-32464] ActionText ContentAttachment’s can Contain Unsanitized HTML |
Cross-site Scripting (XSS) - Stored |
ooooooo_q |
Medium |
2024-06-30 |
| Proxy-Authorization header not cleared on cross-origin redirect in undici.request |
Information Disclosure |
iylz |
Low |
2024-05-29 |
| Path traversal by monkey-patching Buffer internals |
Path Traversal |
tniessen |
High |
2024-05-29 |
| Improper handling of wildcards in --allow-fs-read and --allow-fs-write |
Improper Access Control - Generic |
tniessen |
Medium |
2024-05-29 |
| [CVE-2024-26146] Header Parsing leads to Possible Denial of Service Vulnerability |
Uncontrolled Resource Consumption |
svalkanov |
Low |
2024-05-24 |
| [CVE-2024-26142] ReDoS vulnerability in Accept header parsing in Action Dispatch |
Uncontrolled Resource Consumption |
svalkanov |
Low |
2024-05-22 |
| [CVE-2024-25126] Denial of Service Vulnerability in Rack Content-Type Parsing |
Uncontrolled Resource Consumption |
svalkanov |
Low |
2024-05-22 |
| CVE-2019-1551: rsaz_512_sqr overflow bug on x86_64 |
Cryptographic Issues - Generic |
guido |
No rating |
2024-05-09 |
| Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash |
Uncontrolled Resource Consumption |
bart |
High |
2024-04-29 |
| CVE-2024-25128: Apache Airflow: Authentication Bypass when Legacy OpenID(2.0) is in use as AUTH_TYPE |
Improper Authentication - Generic |
parantheses |
Medium |
2024-04-28 |
| CVE-2024-27351: Potential regular expression denial-of-service in django.utils.text.Truncator.words() |
Uncontrolled Resource Consumption |
scyoon |
Medium |
2024-04-28 |
| Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames |
Uncontrolled Resource Consumption |
bart |
Medium |
2024-04-24 |
| CVE-2024-2398: HTTP/2 push headers memory-leak |
None supplied |
w0x42 |
Medium |
2024-04-22 |
| Denial of Service caused by HTTP/2 CONTINUATION Flood |
Uncontrolled Resource Consumption |
bart |
High |
2024-04-22 |
| CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc |
None supplied |
ooooooo_q |
High |
2024-03-29 |
| Libuv: Improper Domain Lookup that potentially leads to SSRF attacks |
Server-Side Request Forgery (SSRF) |
hunt1 |
High |
2024-03-29 |
| CVE-2024-2466: TLS certificate check bypass with mbedTLS (reward request) |
Improper Certificate Validation |
frankyueh |
Medium |
2024-03-29 |
| CVE-2024-2379: QUIC certificate check bypass with wolfSSL |
Improper Certificate Validation |
fullmetal5 |
Low |
2024-03-29 |
| Usage of disabled protocol in curl |
Cleartext Transmission of Sensitive Information |
dfandrich |
Low |
2024-03-29 |
| CVE-2024-0853: OCSP verification bypass with TLS session reuse |
None supplied |
kurohiro |
Low |
2024-03-27 |
| Proxy-Authorization header is not cleared in cross-domain redirect in undici |
Information Disclosure |
timon8 |
Low |
2024-03-12 |
| Apache Airflow: Bypass permission verification to read code of other dags |
Improper Access Control - Generic |
timon8 |
Low |
2024-03-12 |
| http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks |
Uncontrolled Resource Consumption |
bart |
High |
2024-03-05 |
| Command Injection using malicious hostname in expanded proxycommand |
Code Injection |
vx01 |
Low |
2024-02-28 |
| Request Smuggling in Apache Tomcat (Important, CVE-2023-45648) |
HTTP Request Smuggling |
mukeran |
High |
2024-02-07 |
| CVE-2024-21733 Apache Tomcat HTTP Request Smuggling (Client- Side Desync) (CWE: 444) |
HTTP Request Smuggling |
xer0dayz |
High |
2024-01-29 |
| Argo CD CSRF leads to Kubernetes cluster compromise |
Cross-Site Request Forgery (CSRF) |
tint0 |
High |
2024-01-29 |
| Pickle deserialization vulnerability in XComs |
Deserialization of Untrusted Data |
zpbrent |
Low |
2024-01-29 |
| curl HSTS long file name clears contents |
Missing Encryption of Sensitive Data |
cxshakal |
Low |
2024-01-20 |
| ASAR Integrity bypass via filetype confusion |
None supplied |
marshallofsound |
Medium |
2024-01-20 |
| Cookie headers are not cleared in cross-domain redirect in undici-fetch |
Information Disclosure |
ranjit_p |
Low |
2024-01-20 |
| Path traversal through path stored in Uint8Array in Node.js 20 |
Path Traversal |
tniessen |
High |
2024-01-20 |
| CVE-2023-49920: Apache Airflow: Missing CSRF protection on DAG/trigger |
Cross-Site Request Forgery (CSRF) |
itztrq |
Medium |
2024-01-09 |
| Possibility of Request smuggling attack |
HTTP Request Smuggling |
aimotonorihito |
High |
2023-12-22 |
| curl cookie mixed case PSL bypass |
Information Exposure Through Sent Data |
nyymi |
Medium |
2023-12-22 |
| OpenSSL vulnerable to the Marvin Attack (CVE-2022-4304) |
Information Exposure Through Timing Discrepancy |
hkario |
Medium |
2023-12-21 |
| Misconfiguration in AWS CloudFront CDN configuration makes rubygems.org serve (and cache) content from a unclaimed S3-bucket |
Misconfiguration |
p4fg |
Medium |
2023-12-07 |
| Integrity checks according to policies can be circumvented in Node.js 20 and Node.js 18 |
Insufficient Verification of Data Authenticity |
tniessen |
Medium |
2023-11-30 |
| Permission model improperly protects against path traversal in Node.js 20 |
Path Traversal |
tniessen |
High |
2023-11-30 |
| Permissions policies can be bypassed via Module._load and require.extensions (High) (CVE-2023-30587) |
Improper Access Control - Generic |
mattaustin |
High |
2023-11-30 |
| CVE-2023-47037: Airflow Broken Access Control Vulnerability |
Improper Authorization |
itztrq |
Low |
2023-11-29 |
| CVE-2023-46695: Potential denial of service vulnerability in UsernameField on Windows |
Uncontrolled Resource Consumption |
mprogrammer |
Medium |
2023-11-29 |
| CVE-2023-42780: Apache Airflow: Improper access control vulnerability in the "List dag warnings" feature |
Improper Access Control - Generic |
balis0ng |
Low |
2023-11-29 |
| Secrets can be unmasked in the "Rendered Template" |
Information Disclosure |
klexadoc |
Medium |
2023-11-29 |
| [CVE-2023-38546] cookie injection with none file |
None supplied |
w0x42 |
Low |
2023-11-23 |
| CVE-2023-42663: Apache Airflow: Bypass permission verification to view task instances of other dags |
None supplied |
balis0ng |
Low |
2023-11-13 |
| CVE-2023-40611: Apache Airflow Dag Runs Broken Access Control Vulnerability |
Improper Access Control - Generic |
x_h1 |
Low |
2023-10-27 |
| (CVE-2023-32006) Permissions policies can impersonate other modules in using module.constructor.createRequire() |
None supplied |
haxatron1 |
Medium |
2023-10-08 |
| Context isolation bypass via nested unserializable return value |
Privilege Escalation |
marshallofsound |
Medium |
2023-10-07 |
| (CVE-2023-32003) fs.mkdtemp() and fs.mkdtempSync() are missing getValidatedPath() checks |
None supplied |
haxatron1 |
Low |
2023-10-07 |
| (CVE-2023-32004) Permission model bypass by specifying a path traversal sequence in a Buffer |
Path Traversal |
haxatron1 |
High |
2023-10-07 |
| OpenSSL engines can be used to bypass and/or disable the Node.js permission model |
Privilege Escalation |
tniessen |
Medium |
2023-10-07 |
| CVE-2023-30587 Process-based permissions can be bypassed with the "inspector" module. |
Improper Access Control - Generic |
mattaustin |
High |
2023-09-30 |
| [curl] CVE-2023-38039: HTTP header allocation DOS |
Allocation of Resources Without Limits or Throttling |
selmelc |
Medium |
2023-09-27 |
| Apache Airflow path traversal by authenticated user |
Path Traversal |
kietna20 |
Low |
2023-09-14 |
| Potential NULL dereference in libssh's sftp server |
NULL Pointer Dereference |
wct |
Low |
2023-09-14 |
| Regular Expression Denial of Service (ReDoS) Vulnerability before 2.6.3 |
Uncontrolled Resource Consumption |
m3ss1_neo |
Low |
2023-09-14 |
| SSRF Vulnerability through Connection test feature |
Server-Side Request Forgery (SSRF) |
sayoojbkumar |
Medium |
2023-09-12 |
| Dependency Policy Bypass via process.binding |
Privilege Escalation |
leodog896 |
Medium |
2023-09-09 |
| Argocd's web terminal session doesn't expire |
Insufficient Session Expiration |
bean-zhang |
Medium |
2023-09-09 |
| CVE-2023-40195: Apache Airflow Spark Provider Deserialization Vulnerability RCE |
Deserialization of Untrusted Data |
x_h1 |
Medium |
2023-09-08 |
| [CVE-2023-23913] DOM Based Cross-site Scripting in rails-ujs for contenteditable HTML Elements |
Cross-site Scripting (XSS) - DOM |
ryotak |
Medium |
2023-09-07 |
| CVE-2023-40273: Session fixation in Apache Airflow web interface |
Session Fixation |
leixiao |
Low |
2023-09-04 |
| unsanitized input goes to regex function leads to ReDos that make request hangs |
Uncontrolled Resource Consumption |
shin24 |
Low |
2023-08-28 |
| HTTP Request Smuggling via Empty headers separated by CR |
HTTP Request Smuggling |
yadhukrishnam |
Medium |
2023-08-28 |
| jdbc apache airflow provider code execution vulnerability |
Privilege Escalation |
kmhlyxj0 |
Low |
2023-08-26 |
| odbc apache airflow provider code execution vulnerability |
Privilege Escalation |
kmhlyxj0 |
Medium |
2023-08-26 |
| CVE-2023-36617: ReDoS vulnerability in URI (Ruby) |
None supplied |
ooooooo_q |
Medium |
2023-08-15 |
| [CVE-2023-27531] Possible Deserialization of Untrusted Data vulnerability in Kredis JSON |
Deserialization of Untrusted Data |
ooooooo_q |
High |
2023-08-15 |
| [CVE-2023-27539] Possible Denial of Service Vulnerability in Rack’s header parsing |
None supplied |
ooooooo_q |
Medium |
2023-08-15 |
| Cargo not respecting umask when extracting crate archives |
None supplied |
addisoncrump |
High |
2023-08-15 |
| [curl] CVE-2023-32001: fopen race condition |
Time-of-check Time-of-use (TOCTOU) Race Condition |
selmelc |
Medium |
2023-07-27 |
| [CVE-2022-44570] Possible Denial of Service Vulnerability in Rack’s Range header parsing |
Uncontrolled Resource Consumption |
ooooooo_q |
Low |
2023-07-27 |
| [CVE-2022-44571] Possible Denial of Service Vulnerability in Rack Content-Disposition parsing |
Uncontrolled Resource Consumption |
ooooooo_q |
Low |
2023-07-27 |
| [CVE-2022-44572] Possible Denial of Service Vulnerability in Rack’s RFC2183 boundary parsing |
Uncontrolled Resource Consumption |
ooooooo_q |
Low |
2023-07-27 |
| [CVE-2023-22796] Possible ReDoS based DoS vulnerability in Active Support’s underscore |
Uncontrolled Resource Consumption |
ooooooo_q |
Low |
2023-07-27 |
| [CVE-2023-22799] Possible ReDoS based DoS vulnerability in GlobalID |
Uncontrolled Resource Consumption |
ooooooo_q |
Low |
2023-07-27 |
| CVE-2023-28710 Apache Airflow Spark Provider Arbitrary File Read via JDBC |
Improper Input Validation |
sw0rd1ight |
Medium |
2023-07-12 |
| DiffieHellman doesn't generate keys after setting a key |
Cryptographic Issues - Generic |
bensmyth |
Medium |
2023-06-30 |
| CVE-2023-28321: IDN wildcard match |
Improper Certificate Validation |
kurohiro |
Low |
2023-06-25 |
| CVE-2023-28322: more POST-after-PUT confusion |
None supplied |
kurohiro |
Low |
2023-06-25 |
| CVE-2023-28319: UAF in SSH sha256 fingerprint check |
Use After Free |
wct |
Medium |
2023-06-25 |
| CVE-2023-28320 - siglongjmp race condition |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
nyymi |
Low |
2023-05-26 |
| Authenticated but unauthorized users may enumerate Application names via the API |
Information Exposure Through an Error Message |
bean-zhang |
Medium |
2023-05-25 |
| Privilege Esacalation at Apache Airflow 2.5.1 |
None supplied |
ksw9722 |
Medium |
2023-05-18 |
| Possible DoS Vulnerability in Multipart MIME parsing in rack |
Uncontrolled Resource Consumption |
das7pad |
Low |
2023-04-27 |
| CVE-2023-28755: ReDoS vulnerability in URI |
Uncontrolled Resource Consumption |
dee-see |
Medium |
2023-04-26 |
| ReDoS( Ruby, Time) |
Uncontrolled Resource Consumption |
ooooooo_q |
High |
2023-04-26 |
| CVE-2023-27538: SSH connection too eager reuse still |
Business Logic Errors |
nyymi |
Low |
2023-04-19 |
| JWT audience claim is not verified |
Missing Critical Step in Authentication |
farcaller |
Critical |
2023-04-16 |
| Apache Airflow Google Cloud Sql Provider Remote Command Execution |
Improper Input Validation |
sw0rd1ight |
Medium |
2023-04-16 |
| CVE-2023-25692: Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service and Remote Command Execution |
Improper Input Validation |
sw0rd1ight |
Low |
2023-04-16 |
| Security Unfavorable Specifications and Implementations in the CGI::Cookie Class |
None supplied |
ht0k |
Low |
2023-04-09 |
| Ruby's CGI library has HTTP response splitting (HTTP header injection), leaking confidential information |
None supplied |
ht0k |
High |
2023-04-09 |
| Use of Cryptographically Weak Pseudo-Random Number Generator in WebCrypto keygen |
None supplied |
imhunternull |
High |
2023-04-09 |
| Inadequate Encryption Strength in nodejs-current reads openssl.cnf from /home/iojs/build/... upon startup on MacOS |
Cryptographic Issues - Generic |
zdg0x0 |
Medium |
2023-04-09 |
| HTTP Request Smuggling Due to Incorrect Parsing of Header Fields |
HTTP Request Smuggling |
vwx7 |
Medium |
2023-04-09 |
| CRLF Injection in Nodejs ‘undici’ via host |
CRLF Injection |
timon8 |
Medium |
2023-03-29 |
| CVE-2023-23919: Multiple OpenSSL error handling issues in nodejs crypto library |
Cryptographic Issues - Generic |
nobacktrack |
Medium |
2023-03-29 |
| Open Redirect Vulnerability in Action Pack |
Open Redirect |
wonda_tea_coffee |
Medium |
2023-03-26 |
| CVE-2023-27537: HSTS double-free |
Double Free |
kurohiro |
Low |
2023-03-23 |
| Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522) |
HTTP Response Splitting |
nyxsorcerer |
Medium |
2023-03-23 |
| CVE-2023-27536: GSS delegation too eager connection re-use |
Business Logic Errors |
nyymi |
Low |
2023-03-20 |
| CVE-2023-27535: FTP too eager connection reuse |
Business Logic Errors |
nyymi |
Medium |
2023-03-20 |
| CVE-2023-27534: SFTP path ~ resolving discrepancy |
Business Logic Errors |
nyymi |
Low |
2023-03-20 |
| CVE-2023-27533: TELNET option IAC injection |
Business Logic Errors |
nyymi |
Low |
2023-03-20 |
| Potential DoS vulnerability in Django in multipart parser |
Uncontrolled Resource Consumption |
das7pad |
Medium |
2023-03-20 |
| UAF in OpenSSL up to 3.0.7 |
Use After Free |
ogalland |
Medium |
2023-03-18 |
| RCE vulnerability in apache-airflow-providers-apache-sqoop 3.1.0 |
Code Injection |
leixiao |
Medium |
2023-03-18 |
| Argo CD reconciles apps outside configured namespaces when sharding is enabled |
Improper Access Control - Generic |
czchen |
High |
2023-03-05 |
| HTTP multi-header compression denial of service |
Allocation of Resources Without Limits or Throttling |
monnerat |
Medium |
2023-02-24 |
| CVE-2023-23914: HSTS ignored on multiple requests |
Business Logic Errors |
nyymi |
Low |
2023-02-24 |
| CVE-2023-23915: HSTS amnesia with --parallel |
Business Logic Errors |
nyymi |
Low |
2023-02-24 |
| CVE-2022-43551: Another HSTS bypass via IDN |
Cleartext Transmission of Sensitive Information |
kurohiro |
Medium |
2023-02-03 |
| Rails ActionView sanitize helper bypass leading to XSS using SVG tag. |
Cross-site Scripting (XSS) - Generic |
haqpl |
Medium |
2023-01-29 |
| DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices) |
Improper Access Control - Generic |
zeyu2001 |
High |
2023-01-12 |
| CVE-2022-40127: RCE in Apache Airflow <2.4.0 bash example |
Code Injection |
leixiao |
High |
2023-01-05 |
| CVE-2022-23520: Incomplete fix for CVE-2022-32209 (XSS in Rails::Html::Sanitizer under certain configurations) |
Cross-site Scripting (XSS) - Generic |
0b5cur17y |
Medium |
2023-01-04 |
| CVE-2022-23519: Rails::Html::SafeListSanitizer vulnerable to XSS when certain tags are allowed (math+style || svg+style) |
Cross-site Scripting (XSS) - Generic |
0b5cur17y |
Medium |
2023-01-04 |
| Leak of sensitive values to Airflow rendered template |
Insecure Storage of Sensitive Information |
jrs53 |
Low |
2022-12-27 |
| ReDoS (Rails::Html::PermitScrubber.scrub_attribute) |
None supplied |
ooooooo_q |
High |
2022-12-14 |
| Electron CVE-2022-35954 Delimiter Injection Vulnerability in exportVariable |
None supplied |
hackeronanywhere |
Medium |
2022-12-14 |
| CVE-2022-35260: .netrc parser out-of-bounds access |
Stack Overflow |
kurohiro |
Low |
2022-12-03 |
| POST following PUT confusion |
Information Disclosure |
robbotic |
Medium |
2022-12-02 |
| CVE-2022-45402: Apache Airflow: Open redirect during login |
Open Redirect |
bugra |
Medium |
2022-12-01 |
| potential denial of service attack via the locale parameter |
Uncontrolled Resource Consumption |
benjaoming_realone |
Medium |
2022-11-28 |
| CVE-2022-35252: control code in cookie denial of service |
Improper Input Validation |
haxatron1 |
Low |
2022-11-05 |
| CVE-2022-42916: HSTS bypass via IDN |
Cleartext Transmission of Sensitive Information |
kurohiro |
Medium |
2022-11-03 |
| [CVE-2022-35949]: undici.request vulnerable to SSRF using absolute / protocol-relative URL on pathname |
Server-Side Request Forgery (SSRF) |
haxatron1 |
Medium |
2022-09-23 |
| CVE-2022-35948: CRLF Injection in Nodejs ‘undici’ via Content-Type |
CRLF Injection |
x_h1 |
Medium |
2022-09-23 |
| CVE-2022-38362: Apache Airflow Docker Provider <3.0 RCE vulnerability in example dag |
Command Injection - Generic |
x_h1 |
High |
2022-09-23 |
| Airflow Daemon Mode Insecure Umask Privilege Escalation |
Incorrect Permission Assignment for Critical Resource |
nyymi |
Medium |
2022-09-17 |
| CVE-2022-21831: Possible code injection vulnerability in Rails / Active Storage |
Code Injection |
gquadros_ |
High |
2022-09-10 |
| Pause-based desync in Apache HTTPD |
HTTP Request Smuggling |
albinowax |
High |
2022-08-25 |
| Disabling context isolation, nodeIntegrationInSubFrames using an unauthorised frame. |
Improper Access Control - Generic |
s1r1u5 |
Medium |
2022-08-11 |
| Off-by-slash vulnerability in nodejs.org and iojs.org |
Path Traversal |
nagaro |
Medium |
2022-07-28 |
| Node.js - DLL Hijacking on Windows |
Untrusted Search Path |
yakirka |
High |
2022-07-25 |
| CVE-2022-27781: CERTINFO never-ending busy-loop |
Uncontrolled Resource Consumption |
sybr |
Low |
2022-07-24 |
| Rack CVE-2022-30122: Denial of Service Vulnerability in Rack Multipart Parsing |
None supplied |
ooooooo_q |
Medium |
2022-07-23 |
| CVE-2022-32214 - HTTP Request Smuggling Due To Improper Delimiting of Header Fields |
HTTP Request Smuggling |
zeyu2001 |
Medium |
2022-07-22 |
| CVE-2022-32213 - HTTP Request Smuggling Due to Flawed Parsing of Transfer-Encoding |
HTTP Request Smuggling |
zeyu2001 |
Medium |
2022-07-22 |
| CVE-2022-32215 - HTTP Request Smuggling Due to Incorrect Parsing of Multi-line Transfer-Encoding |
HTTP Request Smuggling |
zeyu2001 |
Medium |
2022-07-22 |
| Undici ProxyAgent vulnerable to MITM |
Improper Certificate Validation |
pimterry |
High |
2022-07-13 |
| rubygems.org Batching attack to `confirmation_token` by bypass rate limit |
None supplied |
ooooooo_q |
Low |
2022-07-13 |
| DoS via lua_read_body() [zhbug_httpd_94] |
Uncontrolled Resource Consumption |
tdp3kel9g |
Low |
2022-07-09 |
| Apache HTTP Server: mod_proxy_ajp: Possible request smuggling |
None supplied |
ricterz |
Medium |
2022-07-09 |
| Read beyond bounds via ap_rwrite() [zhbug_httpd_47.2] |
Information Disclosure |
tdp3kel9g |
Low |
2022-07-09 |
| Read beyond bounds in mod_isapi.c [zhbug_httpd_41] |
Buffer Over-read |
tdp3kel9g |
Low |
2022-07-09 |
| Controllable read beyond bounds in lua_websocket_readbytes() [zhbug_httpd_126] |
Information Disclosure |
tdp3kel9g |
Low |
2022-07-09 |
| Read beyond bounds in ap_strcmp_match() [zhbug_httpd_47.7] |
Information Disclosure |
tdp3kel9g |
Low |
2022-07-09 |
| CVE-2022-32208: FTP-KRB bad message verification |
Business Logic Errors |
nyymi |
Low |
2022-06-27 |
| CVE-2022-32206: HTTP compression denial of service |
Allocation of Resources Without Limits or Throttling |
nyymi |
Medium |
2022-06-27 |
| CVE-2022-32205: Set-Cookie denial of service |
Allocation of Resources Without Limits or Throttling |
nyymi |
Low |
2022-06-27 |
| CVE-2022-32207: Unpreserved file permissions |
Business Logic Errors |
nyymi |
Medium |
2022-06-27 |
| Rails::Html::SafeListSanitizer vulnerable to xss attack in an environment that allows the style tag |
Cross-site Scripting (XSS) - Generic |
windshock |
Medium |
2022-06-27 |
| CVE-2022-30115: HSTS bypass via trailing dot |
Cleartext Transmission of Sensitive Information |
haxatron1 |
Medium |
2022-06-11 |
| CVE-2022-27780: percent-encoded path separator in URL host |
Improper Input Validation |
haxatron1 |
Medium |
2022-06-11 |
| CVE-2022-27779: cookie for trailing dot TLD |
Information Exposure Through Sent Data |
haxatron1 |
Medium |
2022-06-11 |
| CVE-2022-28738: Double free in Regexp compilation |
Double Free |
piao |
High |
2022-05-28 |
| CVE-2022-27778: curl removes wrong file on error |
Business Logic Errors |
nyymi |
Medium |
2022-05-12 |
| CVE-2022-27782: TLS and SSH connection too eager reuse |
Business Logic Errors |
nyymi |
Medium |
2022-05-12 |
| OAUTH2 bearer not-checked for connection re-use |
Improper Authentication - Generic |
monnerat |
Medium |
2022-04-29 |
| CVE-2022-27776: Auth/cookie leak on redirect |
Insufficiently Protected Credentials |
nyymi |
Low |
2022-04-29 |
| CVE-2022-27775: Bad local IPv6 connection reuse |
Information Disclosure |
nyymi |
Low |
2022-04-29 |
| CVE-2022-27774: Credential leak on redirect |
Insufficiently Protected Credentials |
nyymi |
Medium |
2022-04-29 |
| Renderers can obtain access to random bluetooth device without permission |
Improper Access Control - Generic |
palmeral |
Low |
2022-04-23 |
| Read and write beyond bounds in mod_sed |
Heap Overflow |
tdp3kel9g |
High |
2022-04-14 |
| CVE-2022-24288: Apache Airflow: TWO RCEs in example DAGs |
Command Injection - Generic |
x_h1 |
High |
2022-04-01 |
| Time-of-check to time-of-use vulnerability in the std::fs::remove_dir_all() function of the Rust standard library |
Time-of-check Time-of-use (TOCTOU) Race Condition |
hkratz |
High |
2022-03-24 |
| Regexes with large repetitions on empty sub-expressions take a very long time to parse |
Uncontrolled Resource Consumption |
addisoncrump |
High |
2022-03-22 |
| Use of uninitialized value of in req_parsebody method of lua_request.c |
Uncontrolled Resource Consumption |
chamal |
Medium |
2022-03-17 |
| Ruby CVE-2021-41819: Cookie Prefix Spoofing in CGI::Cookie.parse |
Reliance on Cookies without Validation and Integrity Checking in a Security Decision |
ooooooo_q |
High |
2022-02-03 |
| Buffer Overflow in optimized_escape_html method |
Classic Buffer Overflow |
chamal |
Medium |
2022-01-22 |
| Invalid handling of X509_verify_cert() internal errors in libssl (CVE-2021-4044) |
Improper Certificate Validation |
tniessen |
Medium |
2022-01-20 |
| Buffer overflow in req_parsebody method in lua_request.c |
Heap Overflow |
chamal |
High |
2022-01-04 |
| Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) (CVE-2021-42013) |
Path Traversal |
fms |
Critical |
2021-11-19 |
| Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.50 |
Path Traversal: '.../...//' |
itsecurityco |
Critical |
2021-11-19 |
| Ruby - Regular Expression Denial of Service Vulnerability of Date Parsing Methods |
Denial of Service |
svalkanov |
Medium |
2021-11-19 |
| The Host Authorization middleware in Action Pack is vulnerable to crafted X-Forwarded-Host values |
Open Redirect |
mshtawythug |
Medium |
2021-11-18 |
| Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
Path Traversal |
monkey_logic |
Critical |
2021-11-09 |
| Request line injection via HTTP/2 in Apache mod_proxy |
None supplied |
albinowax |
Medium |
2021-11-04 |
| "urllib" will result to deny of service |
None supplied |
4nim4l |
Low |
2021-10-21 |
| CVE-2021-3711: SM2 decrypt buffer overflow |
Classic Buffer Overflow |
ouyang |
High |
2021-09-27 |
| 1-byte heap buffer overflow in DNS resolver |
Off-by-one Error |
luismerino |
Medium |
2021-08-27 |
| HTTP Smuggling multiple issues in Squid 3.x & squid 4.x |
HTTP Response Splitting |
regilero |
Critical |
2021-08-26 |
| Basic Authentication Heap Overflow |
Heap Overflow |
jeriko_one |
High |
2021-08-26 |
| Squid leaks previous content from reusable buffer |
Buffer Over-read |
jeriko_one |
High |
2021-08-26 |
| URN Request bypass ACL Checks |
Improper Access Control - Generic |
jeriko_one |
Critical |
2021-08-26 |
| Cache Manager ACL Bypass |
Authentication Bypass Using an Alternate Path or Channel |
jeriko_one |
Critical |
2021-08-26 |
| Cache Poisoning |
Improper Handling of URL Encoding (Hex Encoding) |
jeriko_one |
High |
2021-08-26 |
| Squid as reverse proxy RCE and data leak |
Classic Buffer Overflow |
guido |
Critical |
2021-08-26 |
| UrnState Heap Overflow |
Classic Buffer Overflow |
jeriko_one |
Critical |
2021-08-26 |
| Buffer overflow in PyCArg_repr in _ctypes/callproc.c for Python 3.x to 3.9.1 |
Classic Buffer Overflow |
jordyzomer |
High |
2021-08-25 |
| Two out-of-bounds array reads in Python AST builder (Re-opening 520612 with CVEs) |
Buffer Over-read |
blarsen |
Medium |
2021-08-25 |
| DOMPurify bypass |
Cross-site Scripting (XSS) - Generic |
vovohelo |
Medium |
2020-12-17 |
| Some build dependencies are downloaded over an insecure channel (without subsequent integrity checks) |
Cryptographic Issues - Generic |
jub0bs |
High |
2020-12-04 |
| Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd |
Cryptographic Issues - Generic |
vanhoefm |
Medium |
2020-05-05 |
| Tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option() (CVE-2018-16229) |
Out-of-bounds Read |
bugbasher |
Critical |
2020-02-13 |
| Tcpdump before 4.9.3 has a buffer over-read in print-802_11.c (CVE-2018-16227) |
Out-of-bounds Read |
bugbasher |
Critical |
2020-02-13 |
| tcpdump: CVE-2018-14879 - buffer overflow in tcpdump.c:get_next_file() |
Buffer Underflow |
geeknik |
Critical |
2020-02-13 |
| use-after-free vulnerability in Flash Player |
Memory Corruption - Generic |
yopwn |
No rating |
2019-11-12 |
| Wrong Handling of Content-Type allows Flash injection and Rosseta flash patch bypass |
Cross-site Scripting (XSS) - Generic |
benhayak |
No rating |
2019-11-12 |
| Misusing of FPU Instruction Could Cause Security Vulnerabilities in Adobe Flash Player |
Memory Corruption - Generic |
yopwn |
No rating |
2019-11-12 |
| Adobe Flash Player TextField Use-After-Free Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player Race Condition Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ASnative(101,10) Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ASnative(900,1).call(MovieClip) Use-After-Free Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ASnative(900,1).call(TextField) Use-After-Free Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player Uninitialised Memory Corruption |
Memory Corruption - Generic |
riusksk |
No rating |
2019-11-12 |
| Adobe Flash Player ContentFactory class Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player OpportunityGenerator class Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player Metadata class Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ShimContentFactory class Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ShimContentFactory.retrieveResolvers Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ShimContentResolver.configure Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ShimOpportunityGenerator class Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ShimContentResolver(resolverType=0) class Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ShimContentResolver(resolverType=1) class Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player TimedEvent.parent Memory Corruption Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player ShimAdPolicySelector(adPolicySelectorType=0) class Memory Corruption |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player PSDK Class Use After Free Vulnerability |
Memory Corruption - Generic |
hhj4ck |
No rating |
2019-11-12 |
| Adobe Flash Player Regular Expression UAF Remote Code Execution Vulnerability |
Memory Corruption - Generic |
bee13oy |
No rating |
2019-11-12 |
| User credentials leak and arbitrary local file read/leak due to same-origin-policy violation |
Information Disclosure |
bjornruytenberg |
No rating |
2019-11-12 |
| Perl $ENV Key Stack Buffer Overflow |
Stack Overflow |
johnleitch |
High |
2019-11-12 |
| Stack overflow when decompressing tar archives |
Memory Corruption - Generic |
hji |
No rating |
2019-11-12 |
| openssl_seal() uninitialized memory usage |
Memory Corruption - Generic |
51201 |
No rating |
2019-11-12 |
| Arbitary Memory Read via gdImageRotateInterpolated Array Index Out of Bounds |
Memory Corruption - Generic |
libnex |
No rating |
2019-11-12 |
| Heap BufferOver Flow in escapeshellargs and escapeshellcmd functions |
Memory Corruption - Generic |
libnex |
No rating |
2019-11-12 |
| An integer overflow bug in php_implode() could lead heap overflow, make PHP to crash |
Memory Corruption - Generic |
blue9057 |
No rating |
2019-11-12 |
| PHP-FPM fpm_log.c memory leak and buffer overflow |
Uncontrolled Resource Consumption |
imrerad |
No rating |
2019-11-12 |
| An integer overflow bug in php_str_to_str_ex() led arbitrary code execution. |
Memory Corruption - Generic |
blue9057 |
No rating |
2019-11-12 |
| Use-after-free vulnerability in SPL(ArrayObject, unserialize) |
Code Injection |
seanhn |
No rating |
2019-11-12 |
| Use-after-free vulnerability in SPL(SplObjectStorage, unserialize) |
Code Injection |
seanhn |
No rating |
2019-11-12 |
| Trivial age-old heap overflow in 32-bit PHP |
Code Injection |
jbremer |
No rating |
2019-11-12 |
| Multiple vulnerabilities related to PCRE functions (already fixed) |
Memory Corruption - Generic |
mongo |
No rating |
2019-11-12 |
| _php_mb_regex_ereg_replace_exec - double free |
Memory Corruption - Generic |
51201 |
No rating |
2019-11-12 |
| Invalid free in phar_extract_file() |
Memory Corruption - Generic |
hji |
No rating |
2019-11-12 |
| Heap Overflow Due To Integer Overflow |
Memory Corruption - Generic |
hoangnguyen |
No rating |
2019-11-12 |
| Double Free Corruption in wddx.c (extension) |
Code Injection |
hoangnguyen |
No rating |
2019-11-12 |
| Integer Overflow in _gd2GetHeader() resulting in heap overflow |
Memory Corruption - Generic |
gogil |
No rating |
2019-11-12 |
| NULL Pointer Dereference at _gdScaleVert |
Uncontrolled Resource Consumption |
emyei |
No rating |
2019-11-12 |
| Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow |
Memory Corruption - Generic |
gogil |
No rating |
2019-11-12 |
| Stack-based buffer overflow vulnerability in php_stream_zip_opener |
Code Injection |
knight9 |
No rating |
2019-11-12 |
| Stack-based buffer overflow vulnerability in virtual_file_ex |
Memory Corruption - Generic |
knight9 |
No rating |
2019-11-12 |
| Inadequate error handling in bzread() |
Memory Corruption - Generic |
hji |
No rating |
2019-11-12 |
| heap-buffer-overflow (write) simplestring_addn simplestring.c |
Memory Corruption - Generic |
pjumde |
No rating |
2019-11-12 |
| php mcrypt ext - In correct casting from size_t to int lead to heap overflow in mdecrypt_generic |
Code Injection |
minhrau |
No rating |
2019-11-12 |
| php curl ext size_t overflow lead to heap corruption |
Code Injection |
minhrau |
No rating |
2019-11-12 |
| integer overflow in base64_decode caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in bzdecompress caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| Integer overflow lead to heap corruption in sql_regcase |
Code Injection |
minhrau |
No rating |
2019-11-12 |
| integer overflow in quoted_printable_encode caused heap corruption |
Code Injection |
minhrau |
No rating |
2019-11-12 |
| integer overflow in urlencode caused heap corruption |
Code Injection |
minhrau |
No rating |
2019-11-12 |
| Heap Overflow due to integer overflows |
Memory Corruption - Generic |
knight9 |
No rating |
2019-11-12 |
| integer overflow in php_uuencode caused heap corruption |
Code Injection |
minhrau |
No rating |
2019-11-12 |
| Out of bound when verify signature of zip phar in phar_parse_zipfile |
Memory Corruption - Generic |
hoangnguyen |
No rating |
2019-11-12 |
| Out of bound when verify signature of tar phar in phar_parse_tarfile |
Memory Corruption - Generic |
hoangnguyen |
No rating |
2019-11-12 |
| Heap overflow in curl_escape |
Memory Corruption - Generic |
hoangnguyen |
No rating |
2019-11-12 |
| Memory Leakage In exif_process_IFD_in_TIFF (CVE-2016-7128) |
Memory Corruption - Generic |
hoangnguyen |
No rating |
2019-11-12 |
| integer overflow in pg_escape_string caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in php_ldap_do_escape caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| heap overflow in substr_replace |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in str_pad caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in pg_escape_bytea caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in imap_binary caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in preg_quote caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in fgets cause heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in recode_string caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| memory corruption in wordwrap function |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in fgetcsv caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| integer overflow in xml_utf8_encode |
Memory Corruption - Generic |
ahihi |
No rating |
2019-11-12 |
| Missing type check when unserializing SplArray |
Memory Corruption - Generic |
ahihi |
No rating |
2019-11-12 |
| gzdecode does NOT check output string size which leads to an overflow |
Memory Corruption - Generic |
jot |
No rating |
2019-11-12 |
| gzuncompress does NOT check output string size which leads to an overflow |
Memory Corruption - Generic |
jot |
No rating |
2019-11-12 |
| Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF |
Memory Corruption - Generic |
hoangnguyen |
No rating |
2019-11-12 |
| integer overflow in curl_escape caused heap corruption |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| ldap_escape could produce string larger than 2Gb |
Memory Corruption - Generic |
jot |
No rating |
2019-11-12 |
| Stack Buffer Overflow in GD dynamicGetbuf |
Memory Corruption - Generic |
libnex |
High |
2019-11-12 |
| php_snmp_parse_oid integer overflow in memory allocation |
Memory Corruption - Generic |
fwh |
Low |
2019-11-12 |
| malloc negative size parameter |
Memory Corruption - Generic |
ahihi |
Low |
2019-11-12 |
| crash in locale_compose() function |
Code Injection |
jot |
Low |
2019-11-12 |
| Invalid memory access in spl_filesystem_info_set_filename function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| Invalid memory access in php_basename function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| Invalid memory access in spl_filesystem_dir_open function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| crash in simplestring_addn function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| Invalid memory access in zend_strtod() function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| Heap overflow due to integer overflow in php_escape_html_entities_ex() function |
Memory Corruption - Generic |
fosec |
Low |
2019-11-12 |
| Heap overflow due to integer overflow in pg_escape_string() function |
Memory Corruption - Generic |
fosec |
Low |
2019-11-12 |
| Memory corruption due to missing check size in _php_math_number_format_ex() |
Memory Corruption - Generic |
fosec |
Low |
2019-11-12 |
| Heap overflow due to integer overflow in bzdecompress() function |
Memory Corruption - Generic |
fosec |
Low |
2019-11-12 |
| Memory corruption in _php_math_number_format_ex() |
Memory Corruption - Generic |
fosec |
Low |
2019-11-12 |
| CachingIterator null dereference when convert to string |
Memory Corruption - Generic |
ahihi |
Low |
2019-11-12 |
| another crash in locale_get_keywords function |
Code Injection |
jot |
Low |
2019-11-12 |
| crash in locale_get_keywords() when keyword value in locale string too long |
Code Injection |
jot |
Low |
2019-11-12 |
| crash in get_icu_value_internal function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| crash in bzcompress function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| iconv() function missing string length check |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| crash in implode() function |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| heap overflow in php_ereg_replace function |
Code Injection |
jot |
Low |
2019-11-12 |
| missing NULL check in dom_document_save_html |
Code Injection |
jot |
Low |
2019-11-12 |
| crash in gzcompress and 3 other compress functions |
Memory Corruption - Generic |
jot |
Low |
2019-11-12 |
| crash in openssl_random_pseudo_bytes function |
Code Injection |
jot |
Low |
2019-11-12 |
| NULL pointer dereference in SimpleXMLElement::asXML() |
Code Injection |
jot |
Low |
2019-11-12 |
| Invalid read when wddx decodes empty boolean element |
Memory Corruption - Generic |
fosec |
Medium |
2019-11-12 |
| 3 heap corruptions in PHP |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| NULL Pointer Dereference while unserialize php object |
NULL Pointer Dereference |
hoangnguyen |
Medium |
2019-11-12 |
| Potential infinite loop in gdImageCreateFromGifCtx! |
Uncontrolled Resource Consumption |
orange |
High |
2019-11-12 |
| Inappropriately parsing HTTP response leads to PHP segment fault! |
NULL Pointer Dereference |
orange |
Low |
2019-11-12 |
| UAF in xmlparser_setevents (1) |
Memory Corruption - Generic |
pakt_ |
No rating |
2019-11-12 |
| UAF in xmlparser_setevents (2) |
Memory Corruption - Generic |
pakt_ |
No rating |
2019-11-12 |
| EIP control using type confusion in json encoding |
Code Injection |
pakt_ |
No rating |
2019-11-12 |
| integer overflow in the _csv module's join_append_data function |
None supplied |
tehybel |
No rating |
2019-11-12 |
| integer overflow in binascii.b2a_qp |
None supplied |
tehybel |
No rating |
2019-11-12 |
| Py_DECREF on a non-owned object in the _sre module |
None supplied |
tehybel |
No rating |
2019-11-12 |
| stack buffer overflows in the curses module |
Memory Corruption - Generic |
tehybel |
No rating |
2019-11-12 |
| Two vulnerabilities in the ssl module |
None supplied |
tehybel |
No rating |
2019-11-12 |
| null pointer dereference in set_conversion_mode due uncheck _ctypes_conversion_errors |
Memory Corruption - Generic |
minhrau |
No rating |
2019-11-12 |
| use of uninitialized variables in operator.methodcaller |
None supplied |
tehybel |
No rating |
2019-11-12 |
| Additional information for CVE-2016-5699 |
None supplied |
ecbftw |
No rating |
2019-11-12 |
| Multiple use after frees in obj2ast_* methods |
Memory Corruption - Generic |
pakt_ |
Low |
2019-11-12 |
| Incorrect GC behavior in xxlimited could lead to use-after-free |
Memory Corruption - Generic |
zeroinside |
Low |
2019-11-12 |
| Heap Buffer Overflow |
Memory Corruption - Generic |
b6945caf98f2f809b8e6ece |
Low |
2019-11-12 |
| Use-after-free in _asyncio_Future_remove_done_callback |
Use After Free |
nedw |
Low |
2019-11-12 |
| Urllib connects to a wrong host |
Server-Side Request Forgery (SSRF) |
orange |
Low |
2019-11-12 |
| putty pscp client-side post-auth stack buffer overwrite when processing remote file size |
Memory Corruption - Generic |
hxd |
No rating |
2019-11-12 |
| CVE-2016-5157 OpenJPEG opj_dwt_interleave_v Out-of-Bounds Write Vulnerability |
Memory Corruption - Generic |
binvul |
No rating |
2019-11-12 |
| CVE-2016-7163 OpenJPEG opj_pi_create_decode Integer Overflow Vulnerability |
Memory Corruption - Generic |
binvul |
No rating |
2019-11-12 |
| CVE-2016-3183 OpenJPEG sycc422_to_rgb Out-of-Bounds Read Vulnerability |
Memory Corruption - Generic |
binvul |
No rating |
2019-11-12 |
| CVE-2016-3182 OpenJPEG color_esycc_to_rgb Out-of-Bounds Read Vulnerability |
Memory Corruption - Generic |
binvul |
No rating |
2019-11-12 |
| CVE-2016-4796 OpenJPEG color_cmyk_to_rgb Out-of-Bounds Read Vulnerability |
Memory Corruption - Generic |
binvul |
No rating |
2019-11-12 |
| CVE-2016-1924 OpenJPEG opj_tgt_reset Out-of-Bounds Read Vulnerability |
Memory Corruption - Generic |
binvul |
No rating |
2019-11-12 |
| The “Malstaller” Attack, global hijacking of any installation process to achieve RCE with elevated privileges, Windows OS (vendor agnostic) |
Code Injection |
penrose |
No rating |
2019-11-12 |
| Incorrect logic in MySQL & MariaDB protocol leads to remote SSRF/Remote file read |
Information Disclosure |
squashbroom |
No rating |
2019-11-12 |
| Malicious Server can force read any file on clients system with default configuration in MySQL Clients |
Information Disclosure |
tarq |
No rating |
2019-11-12 |
| RCE on default Ubuntu Desktop >= 12.10 Quantal |
Command Injection - Generic |
donnchac |
Critical |
2019-11-12 |
| CVE-2017-8798 - miniupnp getHTTPResponse chunked encoding integer signedness error |
Integer Overflow |
hxd |
High |
2019-11-12 |
| Roundcube virtualmin privilege escalation (CVE-2017-8114) |
Command Injection - Generic |
ilsani |
Medium |
2019-11-12 |
| Widespread failure of certificate validation in Android apps |
Cryptographic Issues - Generic |
secbro |
No rating |
2019-11-12 |
| Ericsson Erlang OTP Core Allocation Subsystem Integer Overflow (All Versions) |
Memory Corruption - Generic |
donb |
No rating |
2019-11-12 |
| Exim handles BDAT data incorrectly and leads to crash/hang |
Uncontrolled Resource Consumption |
mehqq |
High |
2019-11-12 |
| GarlicRust - heartbleed style vulnerability in major I2P C++ router implementations |
Buffer Over-read |
aerodudrizzt |
High |
2019-11-12 |
| CVE-2017-13089 wget stack smash |
Classic Buffer Overflow |
jalio |
High |
2019-11-12 |
| CVE-2017-13090 wget heap smash |
Classic Buffer Overflow |
jalio |
High |
2019-11-12 |
| Exim use-after-free vulnerability while reading mail header involving BDAT commands |
Use After Free |
mehqq |
Critical |
2019-11-12 |
| Multiple HTTP Smuggling reports |
HTTP Request Smuggling |
regilero |
Critical |
2019-11-12 |
| OpenSSH / dropbearSSHd xauth command injection |
Privilege Escalation |
hxd |
No rating |
2019-11-12 |
| Critical vulnerability in JSON Web Encryption (JWE) - RFC 7516 Invalid Curve attack |
Cryptographic Issues - Generic |
asanso |
High |
2019-11-12 |
| Race condition in Flash workers may cause an exploitable double free |
Memory Corruption - Generic |
biloulehibou |
No rating |
2019-11-12 |
| mod_remoteip stack buffer overflow and NULL pointer dereference |
Classic Buffer Overflow |
ccppuu |
Medium |
2019-11-07 |
| wddx_deserialize use-after-free |
Memory Corruption - Generic |
fms |
No rating |
2019-11-03 |
| wddx_deserialize allows illegal memory access |
Memory Corruption - Generic |
fms |
No rating |
2019-10-31 |
| wddx_deserialize null dereference |
Memory Corruption - Generic |
fms |
No rating |
2019-10-31 |
| pass2_no_dither out-of-bounds access |
Memory Corruption - Generic |
fms |
No rating |
2019-10-31 |
| gdImageTrueColorToPaletteBody allows arbitrary write/read access |
Memory Corruption - Generic |
fms |
No rating |
2019-10-31 |
| select_colors write out-of-bounds |
Memory Corruption - Generic |
fms |
No rating |
2019-10-31 |
| imap_rfc822_parse_headers GS Violation |
Memory Corruption - Generic |
fms |
No rating |
2019-10-31 |
| Illegal write/read access caused by gdImageAALine overflow |
Memory Corruption - Generic |
fms |
Low |
2019-10-31 |
| imagescale out-of-bounds read |
Memory Corruption - Generic |
fms |
No rating |
2019-10-31 |
| Heap-buffer-overflow in Perl__byte_dump_string (utf8.c) could lead to memory leak |
Buffer Over-read |
tmnt53 |
High |
2019-10-24 |
| Int Overflow lead to Heap OverFlow in exif_thumbnail_extract of exif.c |
Integer Overflow |
md4 |
Medium |
2019-10-21 |
| Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079) |
Information Disclosure |
jouko |
No rating |
2019-10-18 |
| Flash Player information disclosure (etc.) CVE-2015-3044, PSIRT-3298 |
Information Disclosure |
jouko |
No rating |
2019-10-18 |
| Flash “local-with-filesystem” Bypass in navigateToURL |
Privilege Escalation |
irsdl |
No rating |
2019-10-17 |
| mod_http2, read-after-free in h2 connection shutdown (CVE-2019-10082) |
Use After Free |
cy1337 |
Medium |
2019-10-15 |
| mod_http2, memory corruption on early pushes (CVE-2019-10081) |
Use After Free |
cy1337 |
High |
2019-10-15 |
| Use-After-Free / Double-Free in WDDX Deserialize |
Memory Corruption - Generic |
l4w |
No rating |
2019-10-15 |
| Out-of-Bound Read in phar_parse_zipfile() |
Memory Corruption - Generic |
l4w |
No rating |
2019-10-15 |
| Heap corruption in tar/zip/phar parser |
Memory Corruption - Generic |
l4w |
No rating |
2019-10-15 |
| Multiple Heap Overflow due to integer overflows | xml/filter_url/addcslashes |
Memory Corruption - Generic |
l4w |
No rating |
2019-10-15 |
| Uninitialized pointer in phar_make_dirstream() |
Memory Corruption - Generic |
l4w |
No rating |
2019-10-15 |
| Integer overflow in wordwrap |
Memory Corruption - Generic |
jakkdu |
No rating |
2019-10-14 |
| Heapoverflow in zipimporter module |
Memory Corruption - Generic |
jakkdu |
No rating |
2019-10-14 |
| external entity expansion in Apache POI |
Information Disclosure |
told_snider |
No rating |
2019-10-14 |
| PHP OpenSSL zif_openssl_seal() heap overflow (wild memcpy) |
Heap Overflow |
xixabangm4 |
Medium |
2019-10-14 |
| PHP WDDX Deserialization Heap OOB Read in timelib_meridian() |
Buffer Over-read |
xixabangm4 |
Medium |
2019-10-14 |
| Out-Of-Bounds Read in timelib_meridian() |
Buffer Over-read |
xixabangm4 |
Medium |
2019-10-14 |
| memory corruption while parsing HTTP response |
Array Index Underflow |
xixabangm4 |
Medium |
2019-10-14 |
| Multiple issues in Libxml2 (2.9.2 - 2.9.5) |
Information Disclosure |
xixabangm4 |
Medium |
2019-10-14 |
| PHP INI Parsing Stack Buffer Overflow Vulnerability |
Classic Buffer Overflow |
xixabangm4 |
Medium |
2019-10-14 |
| memory allocator fails to realloc small block to large one |
Memory Corruption - Generic |
tinduong |
No rating |
2019-10-14 |
| Two vulnerability in GNU binutils |
Out-of-bounds Read |
chihuahua |
Medium |
2019-10-14 |
| rpcbind "rpcbomb" CVE-2017-8779, CVE-2017-8804 |
Uncontrolled Resource Consumption |
guido |
High |
2019-10-14 |
| 4 severe remote + several minor OpenVPN vulnerabilities |
None supplied |
guido |
High |
2019-10-14 |
| CVE-2017-10966: Heap-use-after-free in Irssi <1.0.4 |
Use After Free |
geeknik |
High |
2019-10-14 |
| Null pointer deref with ob_start with compact |
None supplied |
haquaman |
No rating |
2019-10-13 |
| Null pointer deref with ob_start with get_defined_vars |
None supplied |
haquaman |
No rating |
2019-10-13 |
| wddx_deserialize null dereference with invalid xml |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| Integer underflow / arbitrary null write in fread/gzread |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| wddx_deserialize null dereference in php_wddx_pop_element |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| imagecropauto out-of-bounds access |
Memory Corruption - Generic |
fms |
Low |
2019-10-13 |
| Out-of-bounds reads in zif_grapheme_stripos with negative offset |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| imagegif/output out-of-bounds access |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| CVE-2015-8874 Stack overflow with imagefilltoborder |
Uncontrolled Resource Consumption |
fms |
No rating |
2019-10-13 |
| imagegammacorrect allows arbitrary write access |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| Illegal write access through Locale methods |
Memory Corruption - Generic |
fms |
Low |
2019-10-13 |
| locale_accept_from_http out-of-bounds access |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| get_icu_value_internal out-of-bounds read |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| bcpowmod accepts negative scale and corrupts _one_ definition |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| Negative size parameter (-1) in memcpy mbfl_strcut |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| stack-buffer-overflow through "ResourceBundle" methods |
Memory Corruption - Generic |
fms |
Low |
2019-10-13 |
| SEH buffer overflow msgfmt_format_message |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| xml_parse_into_struct segmentation fault |
Memory Corruption - Generic |
fms |
No rating |
2019-10-13 |
| Python 2.7 32-bit JSON encoding heap corruption |
Memory Corruption - Generic |
guido |
Low |
2019-10-13 |
| Use-after-free in PHP7's unserialize() |
Use After Free |
ryat |
Medium |
2019-10-13 |
| Create an Unexpected Object and Don't Invoke __wakeup() in Deserialization |
None supplied |
ryat |
Medium |
2019-10-13 |
| Use After Free in unserialize() |
Use After Free |
ryat |
Medium |
2019-10-13 |
| Type Confusion in Object Deserialization |
Type Confusion |
ryat |
Medium |
2019-10-13 |
| Use-after-free in ArrayObject Deserialization |
Use After Free |
ryat |
Medium |
2019-10-13 |
| Use-after-free in unserialize() |
Memory Corruption - Generic |
ryat |
Medium |
2019-10-13 |
| NULL Pointer Dereference in WDDX Packet Deserialization with PDORow |
Memory Corruption - Generic |
ryat |
Low |
2019-10-13 |
| Use After Free in PHP7 unserialize() |
Memory Corruption - Generic |
ryat |
Medium |
2019-10-13 |
| Memory Corruption in During Deserialized-object Destruction |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Create an Unexpected Object and Don't Invoke __wakeup() in During Deserialization |
None supplied |
ryat |
No rating |
2019-10-13 |
| PHP Session Data Injection Vulnerability |
None supplied |
ryat |
No rating |
2019-10-13 |
| Use After Free Vulnerability in unserialize() |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Use After Free/Double Free in Garbage Collection |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Use After Free Vulnerability in array_walk()/array_walk_recursive() |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Use After Free in unserialize() with Unexpected Session Deserialization |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Use After Free Vulnerability in SNMP with GC and unserialize() |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Integer Overflow/Heap Overflow in json_encode()/json_decode() |
None supplied |
ryat |
No rating |
2019-10-13 |
| Integer Overflow in Length of String-typed ZVAL |
None supplied |
ryat |
No rating |
2019-10-13 |
| Integer Overflow in addcslashes()/addslashes() |
None supplied |
ryat |
No rating |
2019-10-13 |
| Integer Overflow in nl2br() |
None supplied |
ryat |
No rating |
2019-10-13 |
| Integer Overflow in SplFileObject::fread |
None supplied |
ryat |
No rating |
2019-10-13 |
| Multiple Heap Overflows in php_raw_url_encode/php_url_encode |
None supplied |
ryat |
No rating |
2019-10-13 |
| Integer Overflow in php_raw_url_encode |
None supplied |
ryat |
No rating |
2019-10-13 |
| Integer Overflow in php_html_entities() |
None supplied |
ryat |
No rating |
2019-10-13 |
| Type Confusion in WDDX Packet Deserialization |
None supplied |
ryat |
No rating |
2019-10-13 |
| Session WDDX Packet Deserialization Type Confusion Vulnerability |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Type Confusion Vulnerability in PHP_to_XMLRPC_worker() |
None supplied |
ryat |
No rating |
2019-10-13 |
| Use After Free Vulnerability in WDDX Packet Deserialization |
Memory Corruption - Generic |
ryat |
No rating |
2019-10-13 |
| Format string implementation vulnerability, resulting in code execution |
Memory Corruption - Generic |
aerodudrizzt |
Medium |
2019-10-13 |
| potential remote code execution with phar archive |
Code Injection |
vah13 |
No rating |
2019-10-13 |
| Memory corruption when parsing a hostile PHAR archive |
Memory Corruption - Generic |
aerodudrizzt |
Medium |
2019-10-13 |
| Crash (DoS) when parsing a hostile TIFF |
Uncontrolled Resource Consumption |
aerodudrizzt |
Medium |
2019-10-13 |
| Information disclosure in mmap module - python 2.7.12 |
Information Disclosure |
aerodudrizzt |
Low |
2019-10-13 |
| CVE-2017-12858: Heap UAF in _zip_buffer_free() / Double free in _zip_dirent_read() |
Use After Free |
geeknik |
High |
2019-10-08 |
| CVE-2017-13008 The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements(). |
Buffer Over-read |
geeknik |
High |
2019-10-08 |
| CVE-2017-12986 The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print(). |
Buffer Over-read |
geeknik |
High |
2019-10-08 |
| CVE-2017-13038 The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:handle_mlppp(). |
Buffer Over-read |
geeknik |
High |
2019-10-08 |
| CVE-2017-13010 The BEEP parser in tcpdump before 4.9.2 has a buffer over-read in print-beep.c:l_strnstart(). |
Buffer Over-read |
geeknik |
High |
2019-10-08 |
| CVE-2017-13009 The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_print(). |
Buffer Over-read |
geeknik |
High |
2019-10-08 |
| CVE-2017-12985: The IPv6 parser in tcpdump before 4.9.2 has a buffer over-read in ip6_print() |
Buffer Over-read |
geeknik |
High |
2019-10-08 |
| CVE-2017-5482 The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(). |
Memory Corruption - Generic |
geeknik |
High |
2019-10-08 |
| CVE-2017-5342 In tcpdump before 4.9.0 a bug in multiple protocol parsers could cause a buffer overflow in print-ether.c:ether_print() |
Memory Corruption - Generic |
geeknik |
High |
2019-10-08 |
| CVE-2017-5484 The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print() |
Memory Corruption - Generic |
geeknik |
High |
2019-10-08 |
| CVE-2017-5341 The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print() |
Memory Corruption - Generic |
geeknik |
High |
2019-10-08 |
| CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print() |
Memory Corruption - Generic |
geeknik |
High |
2019-10-08 |
| libtiff 4.0.6 heap bufer overflow / out of bounds read (CVE-2016-9273) |
Uncontrolled Resource Consumption |
geeknik |
Medium |
2019-10-04 |
| libtiff 4.0.6 segfault / read outside of buffer (CVE-2016-9297) |
Memory Corruption - Generic |
geeknik |
Medium |
2019-10-04 |
| CVE-2017-11367: Global buffer overflow (READ of size 4) in shoco C library |
Buffer Over-read |
geeknik |
No rating |
2019-10-04 |
| CVE-2017-10965: Null pointer dereference in Irssi <1.0.4 |
NULL Pointer Dereference |
geeknik |
High |
2019-10-04 |
| CVE-2017-5969: libxml2 when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) |
NULL Pointer Dereference |
geeknik |
Medium |
2019-10-04 |
| Denial of service in libxml2, using malicious lzma file to consume available system memory |
Uncontrolled Resource Consumption |
geeknik |
High |
2019-10-04 |
| Use after free with assign by ref to overloaded objects |
Uncontrolled Resource Consumption |
geeknik |
No rating |
2019-10-04 |
| pngcrush double-free/segfault could result in DoS (CVE-2015-7700) |
Uncontrolled Resource Consumption |
geeknik |
No rating |
2019-10-04 |
| pngcrush_measure_idat() off-by-one error (CVE-2015-2158) |
Code Injection |
geeknik |
No rating |
2019-10-04 |
| ChaCha20-Poly1305 with long nonces |
Missing Encryption of Sensitive Data |
jorandirkgreef |
High |
2019-09-30 |
| Silent omission of certificate hostname verification in LibreSSL and BoringSSL |
Improper Certificate Validation |
tiran |
Critical |
2019-09-26 |
| CVE-2019-5736: Escape from Docker and Kubernetes containers to root on host |
Privilege Escalation |
adam_iwaniuk |
High |
2019-09-26 |
| Exim off-by-one RCE vulnerability |
Off-by-one Error |
mehqq |
Critical |
2019-09-26 |
| Mercurial git subrepo lead to arbritary command injection |
Command Injection - Generic |
criticalonly |
Critical |
2019-09-26 |
| [CVE-2018-18313] regcomp: heap-buffer-overflow read in S_grok_bslash_N |
Heap Overflow |
etsukata |
Critical |
2019-09-25 |
| [CVE-2018-18312] regcomp: heap-buffer-overflow write / reg_node overrun |
Heap Overflow |
etsukata |
Critical |
2019-09-25 |
| Windows builds with insecure path defaults (CVE-2019-1552) |
Code Injection |
mirchr |
Low |
2019-09-24 |
| Mailsploit: a sender spoofing bug in over 30 email clients |
User Interface (UI) Misrepresentation of Critical Information |
pwnsdx |
High |
2019-09-19 |
| ZeroMQ libzmq remote code execution |
Memory Corruption - Generic |
guido |
High |
2019-09-12 |
| Linux kernel: CVE-2017-1000112: a memory corruption due to UFO to non-UFO path switch |
Memory Corruption - Generic |
xairy |
High |
2019-09-11 |
| Linux kernel: CVE-2017-7308: a signedness issue in AF_PACKET sockets |
Memory Corruption - Generic |
xairy |
High |
2019-09-11 |
| Industry-Wide MITM Vulnerability Impacting the JVM Ecosystem |
Man-in-the-Middle |
jlleitschuh |
High |
2019-09-10 |
| CVE-2019-0196: mod_http2 with scoreboard Use-After-Free (Read) |
Use After Free |
cy1337 |
Medium |
2019-09-10 |
| [bower] Arbitrary File Write through improper validation of symlinks while package extraction |
Path Traversal |
skyn3t |
High |
2019-09-10 |
| Linux kernel: CVE-2017-6074: DCCP double-free vulnerability |
Double Free |
xairy |
High |
2019-08-27 |
| HTTP MitM on Flash Player settings manager allows attacker to set sandbox settings |
None supplied |
staatseigendom |
No rating |
2018-12-23 |
| Heap Use After Free Read in unserialize() |
Use After Free |
cy1337 |
Medium |
2018-11-27 |
| Out of Bounds Memory Read in unserialize() |
Buffer Over-read |
cy1337 |
Medium |
2018-11-27 |
| Heap Use After Free in unserialize() |
Use After Free |
cy1337 |
Medium |
2018-11-27 |