VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2022-39958HigSep 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily…

  • CVE-2022-28203HigSep 19, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.

  • CVE-2022-37797HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.02

    In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service…

  • CVE-2022-39028HigAug 30, 2022
    risk 0.49cvss 7.5epss 0.02

    telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However,…

  • CVE-2022-22728HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.05

    A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

  • CVE-2021-32862HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS)…

  • CVE-2020-21365HigAug 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.

  • CVE-2022-31780HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2022-31779HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2022-31778HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.

  • CVE-2022-28129HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2021-37150HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2022-2509HigAug 1, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

  • CVE-2022-26306HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was…

  • CVE-2020-7677HigJul 25, 2022
    risk 0.49cvss 8.6epss 0.02

    This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

  • CVE-2021-46828HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.03

    In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.

  • CVE-2020-16093HigJul 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

  • CVE-2022-2048HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no…

  • CVE-2022-32091HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

  • CVE-2022-32088HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

  • CVE-2022-32087HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.

  • CVE-2022-32085HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

  • CVE-2022-32084HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.

  • CVE-2022-32083HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

  • CVE-2022-27775HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.03

    An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

  • CVE-2022-28739HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.04

    There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.

  • CVE-2022-30293HigMay 6, 2022
    risk 0.49cvss 7.5epss 0.02

    In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.

  • CVE-2022-20785HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.07

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…

  • CVE-2022-20771HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.06

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…

  • CVE-2022-21476HigApr 19, 2022
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2.…

  • CVE-2022-27456HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

  • CVE-2022-27452HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.

  • CVE-2022-27449HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.

  • CVE-2022-27448HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

  • CVE-2022-27447HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.

  • CVE-2022-27445HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.

  • CVE-2022-27387HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

  • CVE-2022-27386HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.

  • CVE-2022-27384HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27383HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

  • CVE-2022-27381HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27380HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27379HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27378HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27377HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

  • CVE-2022-27376HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.

  • CVE-2022-24070HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.09

    Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do…

  • CVE-2022-24763HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.02

    PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known…

  • CVE-2021-43666HigMar 24, 2022
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.

  • CVE-2021-44040HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

Page 63 of 210