Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-2ggp-cmvm-f62f
    Fix available
    Packages

    scancodeio

    Summary

    ScanCode.io command injection in docker image fetch process

    Published
    9 Aug 2023
    GHSA-v4gr-v679-42p7
    Fix available
    Packages

    prestashop/prestashop

    Summary

    PrestaShop file deletion via CustomerMessage

    Published
    9 Aug 2023
    GHSA-2rf5-3fw8-qm47
    Fix available
    Packages

    prestashop/prestashop

    Summary

    PrestaShop file deletion via attachment API

    Published
    9 Aug 2023
    GHSA-hpf4-v7v2-95p2
    Fix available
    Packages

    prestashop/prestashop

    Summary

    PrestaShop file access through path traversal

    Published
    9 Aug 2023
    GHSA-xw2r-f8xv-c8xp
    Fix available
    Packages

    prestashop/prestashop, prestashop/prestashop, prestashop/prestashop

    Summary

    PrestaShop XSS injection through Validate::isCleanHTML method

    Published
    9 Aug 2023
    GHSA-gf46-prm4-56pc
    Fix available
    Packages

    prestashop/prestashop, prestashop/prestashop, prestashop/prestashop

    Summary

    PrestaShop SQL manager vulnerability

    Published
    9 Aug 2023
    GHSA-m9r4-3fg7-pqm2
    Fix available
    Packages

    prestashop/prestashop

    Summary

    PrestaShop path traversal

    Published
    9 Aug 2023
    GHSA-75p5-jwx4-qw9h
    Fix available
    Packages

    prestashop/prestashop

    Summary

    PrestaShop boolean SQL injection

    Published
    9 Aug 2023
    GHSA-5824-cm3x-3c38
    Fix available
    Packages

    vyper

    Summary

    Vyper has incorrectly allocated named re-entrancy locks

    Published
    9 Aug 2023
    USN-6243-2
    Fix available
    Packages

    graphite-web

    Summary

    graphite-web regression

    Published
    9 Aug 2023
    CVE-2023-34545
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    OSV-2023-675
    Fix available
    Packages

    flac

    Summary

    Heap-use-after-free in parse_options

    Published
    9 Aug 2023
    OSV-2023-674
    Fix available
    Packages

    pcre2

    Summary

    Heap-buffer-overflow in get_grouplength

    Published
    9 Aug 2023
    OSV-2023-673
    Fix available
    Packages

    pcre2

    Summary

    Heap-buffer-overflow in match

    Published
    9 Aug 2023
    GHSA-876p-8259-xjgg
    Fix available
    Packages

    github.com/libp2p/go-libp2p, github.com/libp2p/go-libp2p, github.com/libp2p/go-libp2p

    Summary

    libp2p nodes vulnerable to attack using large RSA keys

    Published
    9 Aug 2023
    GHSA-c3x7-354f-4p2x
    Fix available
    Packages

    lol-html

    Summary

    lol-html panics on certain HTML inputs

    Published
    9 Aug 2023
    GHSA-p8rx-fwgq-rh2f
    Fix available
    Packages

    Microsoft.NET.Build.Containers

    Summary

    .NET Remote Code Execution Vulnerability

    Published
    9 Aug 2023
    DEBIAN-CVE-2023-33953
    No fix available
    Packages

    grpc, grpc, grpc

    Summary

    Published
    9 Aug 2023
    AZL-27911
    No fix available
    Packages

    grpc

    Summary

    CVE-2023-33953 affecting package grpc 1.42.0-11

    Published
    9 Aug 2023
    AZL-34770
    Fix available
    Packages

    grpc

    Summary

    CVE-2023-33953 affecting package grpc for versions less than 1.62.0-2

    Published
    9 Aug 2023
    AZL-39394
    Fix available
    Packages

    python-tensorboard

    Summary

    CVE-2023-33953 affecting package python-tensorboard for versions less than 2.11.0-2

    Published
    9 Aug 2023
    UBUNTU-CVE-2023-33953
    No fix available
    Packages

    grpc, grpc, grpc, grpc, grpc, grpc, grpc

    Summary

    Published
    9 Aug 2023
    GHSA-p57v-gv7q-4xfm
    Fix available
    Packages

    Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.win-arm64, Microsoft.NetCore.App.Runtime.win-x64, Microsoft.NetCore.App.Runtime.win-x86

    Summary

    .NET Denial of Service Vulnerability

    Published
    9 Aug 2023
    GHSA-vmch-3w2x-vhgq
    Fix available
    Packages

    Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv, Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets

    Summary

    .NET Denial of Service Vulnerability

    Published
    9 Aug 2023
    CVE-2023-33953
    Fix available
    Packages

    ,

    Summary

    Denial-of-Service in gRPC

    Published
    9 Aug 2023
    GHSA-r3hf-q8q7-fv2p
    Fix available
    Packages

    @nguniversal/common

    Summary

    Angular critical CSS inlining Cross-site Scripting Vulnerability Advisory

    Published
    9 Aug 2023
    CVE-2023-32782
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    CVE-2023-32781
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    CVE-2023-31452
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    CVE-2023-31450
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    CVE-2023-31449
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    CVE-2023-31448
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    SUSE-SU-2023:3257-1
    Fix available
    Packages

    pipewire, pipewire, pipewire

    Summary

    Security update for pipewire

    Published
    9 Aug 2023
    SUSE-SU-2023:3256-1
    Fix available
    Packages

    pipewire, pipewire, pipewire

    Summary

    Security update for pipewire

    Published
    9 Aug 2023
    SUSE-SU-2023:3255-1
    Fix available
    Packages

    rubygem-actionpack-4_2, rubygem-actionpack-4_2

    Summary

    Security update for rubygem-actionpack-4_2

    Published
    9 Aug 2023
    USN-4336-3
    Fix available
    Packages

    binutils

    Summary

    binutils vulnerabilities

    Published
    9 Aug 2023
    Packages

    ctdb, ctdb-tests, libsmbclient, libsmbclient-devel, libwbclient, libwbclient-devel, python3-samba, python3-samba-devel, python3-samba-test, samba, samba-client, samba-client-libs, samba-common, samba-common-libs, samba-common-tools, samba-devel, samba-krb5-printing, samba-libs, samba-pidl, samba-test, samba-test-libs, samba-vfs-glusterfs, samba-winbind, samba-winbind-clients, samba-winbind-krb5-locator, samba-winbind-modules, samba-winexe

    Summary

    samba: Fix of 2 CVEs

    Published
    9 Aug 2023
    Packages

    openssh, openssh-askpass, openssh-clients, openssh-ldap, openssh-server, pam_ssh_agent_auth

    Summary

    openssh: Fix of CVE-2023-38408

    Published
    9 Aug 2023
    Packages

    openssh, openssh-askpass, openssh-clients, openssh-ldap, openssh-server, pam_ssh_agent_auth

    Summary

    openssh: Fix of CVE-2023-38408

    Published
    9 Aug 2023
    Packages

    openssh-client, openssh-server, openssh-sftp-server, ssh, ssh-askpass-gnome

    Summary

    Fix CVE(s): CVE-2023-38408

    Published
    9 Aug 2023
    Packages

    ctdb, libnss-winbind, libpam-winbind, libparse-pidl-perl, libsmbclient, libsmbclient-dev, libwbclient-dev, libwbclient0, python-samba, registry-tools, samba, samba-common, samba-common-bin, samba-dev, samba-dsdb-modules, samba-libs, samba-testsuite, samba-vfs-modules, smbclient, winbind

    Summary

    Fix CVE(s): CVE-2023-34966

    Published
    9 Aug 2023
    Packages

    openssh-client, openssh-server, openssh-sftp-server, ssh, ssh-askpass-gnome

    Summary

    Fix CVE(s): CVE-2023-38408

    Published
    9 Aug 2023
    Packages

    openssh-client, openssh-client-ssh1, openssh-server, openssh-sftp-server, ssh, ssh-askpass-gnome, ssh-krb5

    Summary

    Fix CVE(s): CVE-2023-38408

    Published
    9 Aug 2023
    Packages

    openssh-client, openssh-client-ssh1, openssh-server, openssh-sftp-server, ssh, ssh-askpass-gnome, ssh-krb5

    Summary

    Fix CVE(s): CVE-2023-38408

    Published
    9 Aug 2023
    Packages

    ctdb, libnss-winbind, libpam-winbind, libparse-pidl-perl, libsmbclient, libsmbclient-dev, libwbclient-dev, libwbclient0, python-samba, registry-tools, samba, samba-common, samba-common-bin, samba-dev, samba-dsdb-modules, samba-libs, samba-testsuite, samba-vfs-modules, smbclient, winbind

    Summary

    Fix CVE(s): CVE-2023-34966

    Published
    9 Aug 2023
    CVE-2023-24015
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    CVE-2023-23903
    No fix available
    Packages

    Summary

    Published
    9 Aug 2023
    Packages

    bind9, bind9-doc, bind9-host, bind9utils, dnsutils, host, libbind-dev, libbind-export-dev, libbind9-140, libdns-export162, libdns162, libirs-export141, libirs141, libisc-export160, libisc160, libisccc-export140, libisccc140, libisccfg-export140, libisccfg140, liblwres141, lwresd

    Summary

    Fix CVE(s): CVE-2023-2828

    Published
    9 Aug 2023
    GHSA-3vg2-v639-6ch9
    Fix available
    Packages

    magento/community-edition, magento/community-edition, magento/community-edition, magento/community-edition, magento/community-edition, magento/community-edition, magento/project-community-edition

    Summary

    Magento Open Source allows Incorrect Authorization

    Published
    9 Aug 2023
    GHSA-mxc9-g6m4-2v35
    Fix available
    Packages

    magento/community-edition, magento/community-edition, magento/community-edition, magento/community-edition, magento/community-edition, magento/community-edition, magento/project-community-edition

    Summary

    Magento Open Source allows Improper Neutralization of Special Elements Used

    Published
    9 Aug 2023