Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2022-40828
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    CVE-2022-40827
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    CVE-2022-40826
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    CVE-2022-40825
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    CVE-2022-40824
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    GHSA-xrx9-gj26-5wx9
    Fix available
    Packages

    v8n

    Summary

    v8n vulnerable to Inefficient Regular Expression Complexity

    Published
    7 Oct 2022
    GHSA-8r99-h8j2-rw64
    Fix available
    Packages

    twisted

    Summary

    Twisted vulnerable to HTTP Request Smuggling Attacks

    Published
    7 Oct 2022
    GHSA-cg8c-gc2j-2wf7
    No fix available
    Packages

    flask-security

    Summary

    Flask-Security vulnerable to Open Redirect

    Published
    7 Oct 2022
    GHSA-x279-68rr-jp4p
    Fix available
    Packages

    github.com/supranational/blst

    Summary

    Blst vulnerable to incorrect results for some inputs in blst_fp_eucl_inverse function

    Published
    7 Oct 2022
    GHSA-p658-8693-mhvg
    Fix available
    Packages

    github.com/tendermint/tendermint

    Summary

    Tendermint Core vulnerable to Uncontrolled Resource Consumption

    Published
    7 Oct 2022
    GHSA-9jjw-hf72-3mxw
    Fix available
    Packages

    tensorflow, tensorflow-cpu, tensorflow-gpu

    Summary

    TensorFlow vulnerable to heap out of bounds read in filesystem glob matching

    Published
    7 Oct 2022
    GHSA-4xqx-pqpj-9fqw
    Fix available
    Packages

    atlassian/gajira-create

    Summary

    gajira-create GitHub action vulnerable to arbitrary code execution

    Published
    7 Oct 2022
    GHSA-93m7-c69f-5cfj
    Fix available
    Packages

    github.com/antchfx/xmlquery

    Summary

    xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service

    Published
    7 Oct 2022
    GHSA-mqqv-chpx-vq25
    Fix available
    Packages

    github.com/russellhaering/goxmldsig, github.com/russellhaering/gosaml2

    Summary

    goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures

    Published
    7 Oct 2022
    PYSEC-2022-42983
    Fix available
    Packages

    apache-airflow

    Summary

    Published
    7 Oct 2022
    CVE-2022-2929
    Fix available
    Packages

    Summary

    Published
    7 Oct 2022
    Packages

    isc-dhcp, isc-dhcp

    Summary

    Published
    7 Oct 2022
    Packages

    dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp

    Summary

    Published
    7 Oct 2022
    CVE-2022-2928
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    Packages

    isc-dhcp, isc-dhcp

    Summary

    Published
    7 Oct 2022
    Packages

    dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp, dhcp

    Summary

    Published
    7 Oct 2022
    OSV-2022-1022
    Fix available
    Packages

    ndpi

    Summary

    Stack-buffer-overflow in check_content_type_and_change_protocol

    Published
    7 Oct 2022
    OSV-2022-1021
    Fix available
    Packages

    ghostscript

    Summary

    Stack-buffer-underflow in gs_type2_interpret

    Published
    7 Oct 2022
    DLA-3140-1
    Fix available
    Packages

    libpgjava

    Summary

    libpgjava - security update

    Published
    7 Oct 2022
    DLA-3139-1
    Fix available
    Packages

    knot-resolver

    Summary

    knot-resolver - security update

    Published
    7 Oct 2022
    CVE-2022-3422
    Fix available
    Packages

    Summary

    Improper Privilege Management in tooljet/tooljet

    Published
    7 Oct 2022
    CVE-2022-3423
    Fix available
    Packages

    Summary

    Allocation of Resources Without Limits or Throttling in nocodb/nocodb

    Published
    7 Oct 2022
    CVE-2022-39285
    Fix available
    Packages

    Summary

    Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder

    Published
    7 Oct 2022
    CVE-2022-39287
    Fix available
    Packages

    Summary

    Plaintext transmission of CSRF tokens in tiny-csrf

    Published
    7 Oct 2022
    CVE-2022-39289
    Fix available
    Packages

    Summary

    Database log access in ZoneMinder

    Published
    7 Oct 2022
    CVE-2022-39290
    Fix available
    Packages

    Summary

    CSRF key bypass using HTTP methods in zoneminder

    Published
    7 Oct 2022
    CVE-2022-39291
    Fix available
    Packages

    Summary

    Denial of service through logs in zoneminder

    Published
    7 Oct 2022
    CVE-2022-41672
    No fix available
    Packages

    Summary

    Session still functional after user is deactivated

    Published
    7 Oct 2022
    CVE-2022-42092
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    CVE-2022-41414
    No fix available
    Packages

    Summary

    Published
    7 Oct 2022
    Packages

    heimdal, heimdal, heimdal, heimdal, heimdal, heimdal, heimdal, heimdal

    Summary

    Published
    7 Oct 2022
    GHSA-9gp7-6833-wv89
    Fix available
    Packages

    go.etcd.io/etcd/client/v3, go.etcd.io/etcd/client/v3

    Summary

    etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery

    Published
    6 Oct 2022
    GHSA-528j-9r78-wffx
    Fix available
    Packages

    go.etcd.io/etcd/client/v3, go.etcd.io/etcd/client/v3

    Summary

    etcd user credentials are stored in WAL logs in plaintext

    Published
    6 Oct 2022
    CVE-2022-26238
    No fix available
    Packages

    Summary

    Published
    6 Oct 2022
    CVE-2022-26236
    No fix available
    Packages

    Summary

    Published
    6 Oct 2022
    GHSA-4993-m7g5-r9hh
    Fix available
    Packages

    go.etcd.io/etcd/client/v3, go.etcd.io/etcd/client/v3

    Summary

    etcd has no minimum password length

    Published
    6 Oct 2022
    GHSA-h8g9-6gvh-5mrc
    Fix available
    Packages

    go.etcd.io/etcd/v3, go.etcd.io/etcd/v3

    Summary

    etcd vulnerable to TOCTOU of gateway endpoint authentication

    Published
    6 Oct 2022
    GHSA-m332-53r6-2w93
    Fix available
    Packages

    go.etcd.io/etcd/v3, go.etcd.io/etcd/v3

    Summary

    etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic

    Published
    6 Oct 2022
    GHSA-gr7w-x2jp-3xgw
    Fix available
    Packages

    github.com/caddyserver/caddy

    Summary

    Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication

    Published
    6 Oct 2022
    GHSA-398j-f7m7-795j
    Fix available
    Packages

    phpmailer/phpmailer

    Summary

    PHPMailer vulnerable to email header injection

    Published
    6 Oct 2022
    CVE-2022-41355
    No fix available
    Packages

    Summary

    Published
    6 Oct 2022
    CVE-2022-39279
    Fix available
    Packages

    Summary

    Published
    6 Oct 2022
    GHSA-745p-r637-7vvp
    Fix available
    Packages

    codeigniter4/framework

    Summary

    Codeigniter4's Secure or HttpOnly flag set in Config\Cookie is not reflected in Cookies issued

    Published
    6 Oct 2022
    GHSA-m5m3-46gj-wch8
    Fix available
    Packages

    github.com/sylabs/sif/v2

    Summary

    SIF's Digital Signature Hash Algorithms Not Validated

    Published
    6 Oct 2022
    GHSA-px9g-8hgv-jvg2
    Fix available
    Packages

    kamadak-exif

    Summary

    kamadak-exif vulnerable to Infinite loop when parsing PNG files

    Published
    6 Oct 2022