VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2022-0368HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0361HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0359HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0351HigJan 25, 2022
    risk 0.00cvss 7.8epss 0.01

    Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.

  • CVE-2021-45845HigJan 25, 2022
    risk 0.00cvss 7.8epss 0.02

    The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.

  • CVE-2022-23852CriJan 24, 2022
    risk 0.00cvss 9.8epss 0.05

    Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

  • CVE-2022-0319MedJan 21, 2022
    risk 0.00cvss 5.5epss 0.01

    Out-of-bounds Read in vim/vim prior to 8.2.

  • CVE-2022-0318CriJan 21, 2022
    risk 0.00cvss 9.8epss 0.02

    Heap-based Buffer Overflow in vim/vim prior to 8.2.

  • CVE-2022-21704MedJan 19, 2022
    risk 0.00cvss 5.5epss 0.00

    log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any…

  • CVE-2021-4083HigJan 18, 2022
    risk 0.00cvss 7.0epss 0.00

    A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or…

  • CVE-2022-0261HigJan 18, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0213MedJan 14, 2022
    risk 0.00cvss 6.6epss 0.01

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2022-23222HigJan 14, 2022
    risk 0.00cvss 7.8epss 0.02

    kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.

  • CVE-2022-21682HigJan 13, 2022
    risk 0.00cvss 7.7epss 0.02

    Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that…

  • CVE-2021-43860HigJan 12, 2022
    risk 0.00cvss 8.2epss 0.01

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…

  • CVE-2022-22827HigJan 10, 2022
    risk 0.00cvss 8.8epss 0.03

    storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22826HigJan 10, 2022
    risk 0.00cvss 8.8epss 0.03

    nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22825HigJan 10, 2022
    risk 0.00cvss 8.8epss 0.03

    lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22824CriJan 10, 2022
    risk 0.00cvss 9.8epss 0.03

    defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22823CriJan 10, 2022
    risk 0.00cvss 9.8epss 0.03

    build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22822CriJan 10, 2022
    risk 0.00cvss 9.8epss 0.05

    addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2021-46144MedJan 6, 2022
    risk 0.00cvss 6.1epss 0.01

    Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

  • CVE-2021-46142MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

  • CVE-2021-46141MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

  • CVE-2021-41141MedJan 4, 2022
    risk 0.00cvss 5.9epss 0.01

    PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In various parts of PJSIP, when error/failure occurs, it is found that the function returns without…

  • CVE-2021-45960HigJan 1, 2022
    risk 0.00cvss 8.8epss 0.04

    In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

  • CVE-2021-45943MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.01

    GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).

  • CVE-2021-45942MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.02

    OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

  • CVE-2021-45930MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.01

    Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

  • CVE-2021-45958MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.02

    UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.

  • CVE-2021-4193MedDec 31, 2021
    risk 0.00cvss 5.5epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2021-4192HigDec 31, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-43845HigDec 27, 2021
    risk 0.00cvss 8.2epss 0.04

    PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users…

  • CVE-2021-4166HigDec 25, 2021
    risk 0.00cvss 7.1epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2021-45480MedDec 24, 2021
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.

  • CVE-2021-3622MedDec 23, 2021
    risk 0.00cvss 4.3epss 0.05

    A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to…

  • CVE-2021-45469HigDec 23, 2021
    risk 0.00cvss 7.8epss 0.01

    In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.

  • CVE-2021-43804HigDec 22, 2021
    risk 0.00cvss 7.3epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE message contains a reason's length, this declared length is not…

  • CVE-2021-37706HigDec 22, 2021
    risk 0.00cvss 7.3epss 0.05

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not…

  • CVE-2021-45098HigDec 16, 2021
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random…

  • CVE-2021-45095MedDec 16, 2021
    risk 0.00cvss 5.5epss 0.00

    pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.

  • CVE-2021-4069HigDec 6, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Use After Free

  • CVE-2021-3984HigDec 1, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-3973HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-3974HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Use After Free

  • CVE-2021-44025MedNov 19, 2021
    risk 0.00cvss 6.1epss 0.01

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

  • CVE-2021-43976MedNov 17, 2021
    risk 0.00cvss 4.6epss 0.01

    In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).

  • CVE-2021-43975MedNov 17, 2021
    risk 0.00cvss 6.7epss 0.01

    In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.

  • CVE-2021-43114HigNov 9, 2021
    risk 0.00cvss 7.5epss 0.01

    FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.

  • CVE-2021-3928HigNov 5, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Use of Uninitialized Variable

Page 176 of 210