Home/Product/netapp cloud backup
Product

netapp cloud backup

345 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-28656
all versions
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned envir
8.1HIGH
CVE-2021-33068
all versions
Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enab
6.5MEDIUM
CVE-2021-0156
all versions
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an es
7.8HIGH
CVE-2021-0125
all versions
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation
6.6MEDIUM
CVE-2021-0124
all versions
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation
6.6MEDIUM
CVE-2021-0119
all versions
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation
6.2MEDIUM
CVE-2021-0118
all versions
Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of
6.7MEDIUM
CVE-2021-0117
all versions
Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of pri
7.8HIGH
CVE-2021-0116
all versions
Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation o
7.8HIGH
CVE-2021-0115
all versions
Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privi
6.7MEDIUM
CVE-2021-0111
all versions
NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalat
6.7MEDIUM
CVE-2021-0107
all versions
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation o
6.7MEDIUM
CVE-2021-0103
all versions
Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enabl
6.7MEDIUM
CVE-2021-0099
all versions
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially e
7.8HIGH
CVE-2021-0093
all versions
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a den
4.4MEDIUM
CVE-2021-0092
all versions
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of
4.4MEDIUM
CVE-2021-0091
all versions
Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an es
7.8HIGH
CVE-2021-0060
all versions
Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.03
6.6MEDIUM
CVE-2021-44790
all versions
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua script
9.8CRITICAL
CVE-2021-4044
all versions
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That functi
7.5HIGH
CVE-2021-43527
all versions
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded D
9.8CRITICAL
CVE-2018-25020
all versions
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner
7.8HIGH
CVE-2021-43976
all versions
In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can con
4.6MEDIUM
CVE-2021-43975
all versions
In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allow
6.7MEDIUM
CVE-2021-42377
all versions
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processin
9.8CRITICAL
CVE-2021-42376
all versions
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to mis
5.5MEDIUM
CVE-2021-42375
all versions
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell comm
5.5MEDIUM
CVE-2021-42374
all versions
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed
5.3MEDIUM
CVE-2021-42373
all versions
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument
5.5MEDIUM
CVE-2017-5123
all versions
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
8.8HIGH
CVE-2021-25219
all versions
In BIND 9.3.0 - 9.11.35, 9.12.0 - 9.16.21, and versions 9.9.3-S1 - 9.11.35-S1 and 9.16.8-S1 - 9.16.21-S1 of BIND Supported Preview
5.3MEDIUM
CVE-2021-42013
all versions
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal
9.8CRITICAL
CVE-2021-41773
all versions
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attac
9.8CRITICAL
CVE-2021-41524
all versions
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external
7.5HIGH
CVE-2021-41864
all versions
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eB
7.8HIGH
CVE-2021-22947
all versions
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, t
5.9MEDIUM
CVE-2021-22946
all versions
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (
7.5HIGH
CVE-2021-22945
all versions
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an alr
9.1CRITICAL
CVE-2021-38300
all versions
arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBP
7.8HIGH
CVE-2021-41073
all versions
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PRO
7.8HIGH
CVE-2021-40438
all versions
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue a
9.0CRITICAL
CVE-2021-39275
all versions
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to the
9.8CRITICAL
CVE-2021-36160
all versions
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affe
7.5HIGH
CVE-2021-34798
all versions
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
7.5HIGH
CVE-2021-3634
all versions
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime
6.5MEDIUM
CVE-2021-22925
all versions
curl supports the -t command line option, known as CURLOPT_TELNETOPTIONSin libcurl. This rarely used option is used to send va
5.3MEDIUM
CVE-2021-22924
all versions
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.
3.7LOW
CVE-2021-22923
all versions
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink
5.3MEDIUM
CVE-2021-22922
all versions
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the met
6.5MEDIUM
CVE-2021-32785
all versions
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Rely
5.3MEDIUM
CVE-2021-3541
all versions
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and lea
6.5MEDIUM
CVE-2021-3612
all versions
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the w
7.8HIGH
CVE-2021-22555
all versions
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker t
8.3HIGH
CVE-2021-28691
all versions
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable th
7.8HIGH
CVE-2020-28097
all versions
The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds
5.9MEDIUM
CVE-2021-22901
all versions
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3
8.1HIGH
CVE-2021-22897
all versions
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIP
5.3MEDIUM
CVE-2021-26691
all versions
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overf
9.8CRITICAL
CVE-2020-13938
all versions
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
5.5MEDIUM
CVE-2020-8703
all versions
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13
6.7MEDIUM
CVE-2020-8700
all versions
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalatio
6.7MEDIUM
CVE-2020-8670
all versions
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privil
6.4MEDIUM
CVE-2020-24486
all versions
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denia
5.5MEDIUM
CVE-2020-12360
all versions
Out of bounds read in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation o
7.8HIGH
CVE-2020-12359
all versions
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially
6.8MEDIUM
CVE-2020-12358
all versions
Out of bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of servi
4.4MEDIUM
CVE-2020-12357
all versions
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation
6.7MEDIUM
CVE-2019-25045
all versions
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini
7.8HIGH
CVE-2021-3520
all versions
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer
9.8CRITICAL
CVE-2021-33200
all versions
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01
7.8HIGH
CVE-2020-25669
all versions
A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before su
7.8HIGH
CVE-2020-25668
all versions
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use af
7.0HIGH
CVE-2021-22543
all versions
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead t
7.8HIGH
CVE-2020-25673
all versions
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up
5.5MEDIUM
CVE-2020-25671
all versions
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to
7.8HIGH
CVE-2020-25670
all versions
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privi
7.8HIGH
CVE-2021-33574
all versions
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification t
9.8CRITICAL
CVE-2020-25672
all versions
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
7.5HIGH
CVE-2021-31440
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker mu
7.0HIGH
CVE-2021-3426
all versions
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent us
5.7MEDIUM
CVE-2021-3483
all versions
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list
7.8HIGH
CVE-2019-25044
all versions
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel co
7.8HIGH
CVE-2021-32399
all versions
net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
7.0HIGH
CVE-2020-13529
all versions
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a serve
6.1MEDIUM
CVE-2020-35519
all versions
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bound
7.8HIGH
CVE-2021-3501
all versions
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array i
7.1HIGH
CVE-2021-29489
all versions
Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was
7.6HIGH
CVE-2021-31879
all versions
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-
6.1MEDIUM
CVE-2021-25216
all versions
In BIND 9.5.0 - 9.11.29, 9.12.0 - 9.16.13, and versions BIND 9.11.3-S1 - 9.11.29-S1 and 9.16.8-S1 - 9.16.13-S1 of BIND Supported P
8.1HIGH
CVE-2021-25215
all versions
In BIND 9.0.0 - 9.11.29, 9.12.0 - 9.16.13, and versions BIND 9.9.3-S1 - 9.11.29-S1 and 9.16.8-S1 - 9.16.13-S1 of BIND Supported Pr
7.5HIGH
CVE-2021-25214
all versions
In BIND 9.8.5 - 9.8.8, 9.9.3 - 9.11.29, 9.12.0 - 9.16.13, and versions BIND 9.9.3-S1 - 9.11.29-S1 and 9.16.8-S1 - 9.16.13-S1 of BI
6.5MEDIUM
CVE-2021-23133
all versions
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the
6.7MEDIUM
CVE-2021-3506
all versions
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.
7.1HIGH
CVE-2021-29154
all versions
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute
7.8HIGH
CVE-2021-20284
all versions
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in
5.5MEDIUM
CVE-2021-20197
all versions
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy,
6.3MEDIUM
CVE-2021-28972
all versions
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer
6.7MEDIUM
CVE-2021-28971
all versions
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace appli
5.5MEDIUM
CVE-2021-28964
all versions
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cau
4.7MEDIUM
CVE-2021-28952
all versions
An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overf
7.8HIGH
CVE-2021-28951
all versions
An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (dea
5.5MEDIUM
CVE-2021-28660
all versions
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end
8.8HIGH
CVE-2021-28375
all versions
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent use
7.8HIGH
CVE-2021-27363
all versions
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscs
4.4MEDIUM
CVE-2021-28041
all versions
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent
7.1HIGH
CVE-2021-28039
all versions
An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV
6.5MEDIUM
CVE-2021-28038
all versions
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necess
6.5MEDIUM
CVE-2020-14372
all versions
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot i
7.5HIGH
CVE-2021-20226
all versions
A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial
7.8HIGH
CVE-2020-8625
all versions
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuratio
8.1HIGH
CVE-2021-26932
all versions
An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hyp
5.5MEDIUM
CVE-2021-27219
all versions
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on
7.5HIGH
CVE-2021-27218
all versions
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer
7.5HIGH
CVE-2021-23336
all versions
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and bef
5.9MEDIUM
CVE-2021-26708
all versions
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implement
7.0HIGH
CVE-2021-3156
all versions
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalatio
7.8HIGH
CVE-2021-23239
all versions
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests b
2.5LOW
CVE-2020-36183
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36182
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36180
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36179
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oad
8.1HIGH
CVE-2020-36189
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-36188
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-36187
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36186
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36185
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36184
all versions
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36158
all versions
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remo
8.8HIGH
CVE-2020-35507
all versions
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker wh
5.5MEDIUM
CVE-2020-35496
all versions
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a craf
5.5MEDIUM
CVE-2020-35495
all versions
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump progr
5.5MEDIUM
CVE-2020-35494
all versions
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutil
6.1MEDIUM
CVE-2020-35493
all versions
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a
5.5MEDIUM
CVE-2020-27730
all versions
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilit
9.8CRITICAL
CVE-2020-27825
all versions
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace
5.7MEDIUM
CVE-2020-27786
all versions
A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to iss
7.8HIGH
CVE-2020-16599
all versions
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bi
5.5MEDIUM
CVE-2020-16593
all versions
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bi
5.5MEDIUM
CVE-2020-25692
all versions
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An u
7.5HIGH
CVE-2020-29573
all versions
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if
7.5HIGH
CVE-2020-14305
all versions
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality han
8.1HIGH
CVE-2020-29370
all versions
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required T
7.0HIGH
CVE-2020-29368
all versions
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation
7.0HIGH
CVE-2020-15436
all versions
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a den
6.7MEDIUM
CVE-2020-8760
all versions
Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a privilege
7.8HIGH
CVE-2020-8757
all versions
Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a priv
6.7MEDIUM
CVE-2020-8754
all versions
Out-of-bounds read in subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 ma
7.5HIGH
CVE-2020-8752
all versions
Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45
9.8CRITICAL
CVE-2020-8749
all versions
Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an una
8.8HIGH
CVE-2020-8747
all versions
Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an una
9.1CRITICAL
CVE-2020-8746
all versions
Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unaut
6.5MEDIUM
CVE-2020-8738
all versions
Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to po
6.7MEDIUM
CVE-2020-12356
all versions
Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privi
4.4MEDIUM
CVE-2020-0590
all versions
Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable esca
7.8HIGH
CVE-2020-28196
all versions
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message
7.5HIGH
CVE-2020-25221
all versions
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect refere
7.8HIGH
CVE-2020-15862
all versions
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arb
7.8HIGH
CVE-2020-15861
all versions
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
7.8HIGH
CVE-2020-14356
all versions
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot
7.8HIGH
CVE-2020-15852
all versions
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be
7.8HIGH
CVE-2020-14664
all versions
Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u2
8.3HIGH
CVE-2020-14621
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected a
5.3MEDIUM
CVE-2020-14593
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are
7.4HIGH
CVE-2020-14583
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affec
8.3HIGH
CVE-2020-14581
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are
3.7LOW
CVE-2020-14579
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affec
3.7LOW
CVE-2020-14578
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affec
3.7LOW
CVE-2020-14577
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected a
3.7LOW
CVE-2020-14556
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affec
4.8MEDIUM
CVE-2020-15025
all versions
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumptio
4.4MEDIUM
CVE-2020-14155
all versions
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
5.3MEDIUM
CVE-2020-10757
all versions
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local
7.8HIGH
CVE-2020-13871
all versions
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late
7.5HIGH
CVE-2020-13817
all versions
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system t
7.4HIGH
CVE-2020-13645
all versions
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TL
6.5MEDIUM
CVE-2020-13632
all versions
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
5.5MEDIUM
CVE-2020-13631
all versions
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
5.5MEDIUM
CVE-2020-13630
all versions
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
7.0HIGH
CVE-2020-7656
all versions
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<scr
6.1MEDIUM
CVE-2020-13143
all versions
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without consi
6.5MEDIUM
CVE-2020-12888
all versions
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
5.3MEDIUM
CVE-2020-12771
all versions
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coa
5.5MEDIUM
CVE-2020-12770
all versions
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, ak
6.7MEDIUM
CVE-2020-12769
all versions
An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent c
5.5MEDIUM
CVE-2020-12659
all versions
An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user
6.7MEDIUM
CVE-2020-12653
all versions
An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifie
7.8HIGH
CVE-2020-11023
all versions
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sourc
6.9MEDIUM
CVE-2020-12465
all versions
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.1
6.7MEDIUM
CVE-2020-12464
all versions
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs withou
6.7MEDIUM
CVE-2020-11884
all versions
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated
7.0HIGH
CVE-2020-12243
all versions
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of servic
7.5HIGH
CVE-2020-5867
all versions
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and insta
8.1HIGH
CVE-2020-5865
all versions
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted c
4.8MEDIUM
CVE-2020-2830
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are aff
5.3MEDIUM
CVE-2020-2816
all versions
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6
7.5HIGH
CVE-2020-2805
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affec
8.3HIGH
CVE-2020-2803
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affec
8.3HIGH
CVE-2020-2800
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions
4.8MEDIUM
CVE-2020-2781
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected a
5.3MEDIUM
CVE-2020-2778
all versions
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6
3.7LOW
CVE-2020-2773
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affect
3.7LOW
CVE-2020-2767
all versions
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6
4.8MEDIUM
CVE-2020-2757
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are a
3.7LOW
CVE-2020-2756
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are a
3.7LOW
CVE-2020-2755
all versions
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affec
3.7LOW
CVE-2020-1730
all versions
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) cipher
5.3MEDIUM
CVE-2020-8832
all versions
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on c
5.5MEDIUM
CVE-2019-20636
all versions
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by
6.7MEDIUM
CVE-2020-8835
all versions
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32
7.8HIGH
CVE-2020-5863
all versions
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unpr
8.6HIGH
CVE-2020-10029
all versions
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-b
5.5MEDIUM
CVE-2020-9391
all versions
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the
5.5MEDIUM
CVE-2020-9383
all versions
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of
7.1HIGH
CVE-2020-9327
all versions
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of
7.5HIGH
CVE-2020-8992
all versions
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of se
5.5MEDIUM
CVE-2020-8648
all versions
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/
7.1HIGH
CVE-2019-20388
all versions
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
7.5HIGH
CVE-2019-20386
all versions
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command,
2.4LOW
CVE-2019-18282
all versions
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441
5.3MEDIUM
CVE-2020-2585
all versions
Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u2
5.9MEDIUM
CVE-2019-20372
all versions
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an a
5.3MEDIUM
CVE-2019-20095
all versions
mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases t
5.5MEDIUM
CVE-2019-20054
all versions
In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to
5.5MEDIUM
CVE-2019-19966
all versions
In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause
4.6MEDIUM
CVE-2019-19965
all versions
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandlin
4.7MEDIUM
CVE-2019-19925
all versions
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
7.5HIGH
CVE-2019-19924
all versions
SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sq
5.3MEDIUM
CVE-2019-19923
all versions
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-h
7.5HIGH
CVE-2019-19947
all versions
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/
4.6MEDIUM
CVE-2019-5108
all versions
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vu
6.5MEDIUM
CVE-2019-19926
all versions
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRew
7.5HIGH
CVE-2019-19922
all versions
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to c
5.5MEDIUM
CVE-2019-19880
all versions
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant intege
7.5HIGH
CVE-2019-19646
all versions
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
9.8CRITICAL
CVE-2019-19603
all versions
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
7.5HIGH
CVE-2019-19645
all versions
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in con
5.5MEDIUM
CVE-2019-19448
all versions
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a sy
7.8HIGH
CVE-2019-19447
all versions
In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use
7.8HIGH
CVE-2019-19317
all versions
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attac
9.8CRITICAL
CVE-2019-19377
all versions
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a us
7.8HIGH
CVE-2019-19063
all versions
Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11
4.6MEDIUM
CVE-2019-19061
all versions
A memory leak in the adis_update_scan_mode_burst() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allo
7.5HIGH
CVE-2019-19060
all versions
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows att
7.5HIGH
CVE-2019-19057
all versions
Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel t
3.3LOW
CVE-2019-19054
all versions
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allo
4.7MEDIUM
CVE-2019-19053
all versions
A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11 allows at
7.5HIGH
CVE-2019-19052
all versions
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to
7.5HIGH
CVE-2019-19044
all versions
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow at
7.5HIGH
CVE-2019-14591
all versions
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user t
5.5MEDIUM
CVE-2019-14590
all versions
Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user
5.5MEDIUM
CVE-2019-14574
all versions
Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to p
5.5MEDIUM
CVE-2019-11113
all versions
Buffer overflow in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6618 (DCH) or 21.20.x.5077 (aka15.45.5
4.4MEDIUM
CVE-2019-11111
all versions
Pointer corruption in the Unified Shader Compiler in Intel(R) Graphics Drivers before 10.18.14.5074 (aka 15.36.x.5074) may allow a
7.8HIGH
CVE-2019-11089
all versions
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authen
5.5MEDIUM
CVE-2019-11112
all versions
Memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver before 26.20.100.6813 (DCH) or 26.20.100.6812 may allow an aut
7.8HIGH
CVE-2019-18683
all versions
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalat
7.0HIGH
CVE-2019-2215
all versions
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is requ
7.8HIGH
CVE-2019-16905
all versions
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow
7.8HIGH
CVE-2019-15166
all versions
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
1.6LOW
CVE-2019-5482
all versions
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
9.8CRITICAL
CVE-2019-5481
all versions
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
9.8CRITICAL
CVE-2019-11184
all versions
A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to pot
4.8MEDIUM
CVE-2018-16871
all versions
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is a
7.5HIGH
CVE-2019-13115
all versions
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could
8.1HIGH
CVE-2019-13118
all versions
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid char
5.3MEDIUM
CVE-2019-10160
all versions
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting ve
9.8CRITICAL
CVE-2019-11068
all versions
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access e
9.8CRITICAL
CVE-2019-1559
all versions
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to
5.9MEDIUM
CVE-2019-9169
all versions
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via
9.8CRITICAL
CVE-2018-20796
all versions
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,
7.5HIGH
CVE-2009-5155
all versions
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attac
7.5HIGH
CVE-2019-7317
all versions
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_saf
5.3MEDIUM
CVE-2018-5737
all versions
A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even wh
5.9MEDIUM
CVE-2018-5736
all versions
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of
5.3MEDIUM
CVE-2018-20685
all versions
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or
5.3MEDIUM
CVE-2018-0734
all versions
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variati
5.9MEDIUM
CVE-2018-0735
all versions
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use varia
5.9MEDIUM
CVE-2018-18066
all versions
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthentica
7.5HIGH
CVE-2018-18065
all versions
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authent
6.5MEDIUM
CVE-2018-15919
all versions
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users
5.3MEDIUM
CVE-2018-15473
all versions
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user un
5.3MEDIUM
CVE-2018-8011
all versions
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to
7.5HIGH
CVE-2018-2973
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affec
5.9MEDIUM
CVE-2018-2964
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java
8.3HIGH
CVE-2018-2952
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported version
3.7LOW
CVE-2018-2942
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Jav
8.3HIGH
CVE-2018-2941
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE:
8.3HIGH
CVE-2018-2940
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are
4.3MEDIUM
CVE-2018-2938
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE
9.0CRITICAL
CVE-2018-1333
all versions
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion a
7.5HIGH
CVE-2018-2826
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java
8.3HIGH
CVE-2018-2825
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java
8.3HIGH
CVE-2018-1312
all versions
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks
9.8CRITICAL
CVE-2018-7184
all versions
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to c
7.5HIGH
CVE-2018-6485
all versions
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.
9.8CRITICAL
CVE-2016-10708
all versions
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an
7.5HIGH
CVE-2018-2638
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java
8.3HIGH
CVE-2018-2627
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java
7.5HIGH
CVE-2018-2581
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE:
4.7MEDIUM
CVE-2017-15906
all versions
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, whic
5.3MEDIUM
CVE-2017-10388
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are
7.5HIGH
CVE-2017-10357
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that
5.3MEDIUM
CVE-2017-10356
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions t
6.2MEDIUM
CVE-2017-10355
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions
5.3MEDIUM
CVE-2017-10350
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are aff
5.3MEDIUM
CVE-2017-10349
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affec
5.3MEDIUM
CVE-2017-10348
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are
5.3MEDIUM
CVE-2017-10347
all versions
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affec
5.3MEDIUM
CVE-2017-10346
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are af
9.6CRITICAL
CVE-2017-10345
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versi
3.1LOW
CVE-2017-10309
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java
7.1HIGH
CVE-2017-10295
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions
4.0MEDIUM
CVE-2017-10293
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Javadoc). Supported versions that are affected are Java SE
6.1MEDIUM
CVE-2017-10285
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affect
9.6CRITICAL
CVE-2017-10281
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versi
5.3MEDIUM
CVE-2017-10274
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are J
6.8MEDIUM
CVE-2017-10243
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions tha
6.5MEDIUM
CVE-2017-10198
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions t
6.8MEDIUM
CVE-2017-10193
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are a
3.1LOW
CVE-2017-10176
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions t
7.5HIGH
CVE-2017-10135
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that a
5.9MEDIUM
CVE-2017-10125
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java
7.1HIGH
CVE-2017-10118
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that a
7.5HIGH
CVE-2017-10116
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions t
8.3HIGH
CVE-2017-10115
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that a
7.5HIGH
CVE-2017-10114
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE:
8.3HIGH
CVE-2017-10111
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). The supported version that i
9.6CRITICAL
CVE-2017-10110
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u
9.6CRITICAL
CVE-2017-10109
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versi
5.3MEDIUM
CVE-2017-10108
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versi
5.3MEDIUM
CVE-2017-10107
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affect
9.6CRITICAL
CVE-2017-10105
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java
4.3MEDIUM
CVE-2017-10102
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affect
9.0CRITICAL
CVE-2017-10101
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affec
9.6CRITICAL
CVE-2017-10096
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affec
9.6CRITICAL
CVE-2017-10089
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE
9.6CRITICAL
CVE-2017-10087
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are
9.6CRITICAL
CVE-2017-10086
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE:
9.6CRITICAL
CVE-2017-10081
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are af
4.3MEDIUM
CVE-2017-10078
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported version that is affected is Java
8.1HIGH
CVE-2017-10074
all versions
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are af
8.3HIGH
CVE-2017-10067
all versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java S
7.5HIGH
CVE-2017-10053
all versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that ar
5.3MEDIUM
CVE-2016-9841
all versions
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmet
9.8CRITICAL
CVE-2016-5195
all versions
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging in
7.0HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin