Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    UBUNTU-CVE-2022-21797
    No fix available
    Packages

    joblib, joblib, joblib, joblib, joblib

    Summary

    Published
    26 Sept 2022
    CVE-2022-21797
    Fix available
    Packages

    Summary

    Arbitrary Code Execution

    Published
    26 Sept 2022
    CVE-2022-21169
    Fix available
    Packages

    Summary

    Prototype Pollution

    Published
    26 Sept 2022
    CVE-2022-41347
    No fix available
    Packages

    Summary

    Published
    26 Sept 2022
    OSV-2022-955
    Fix available
    Packages

    lcms

    Summary

    Use-of-uninitialized-value in FileWrite

    Published
    26 Sept 2022
    GHSA-6x28-7h8c-chx4
    Fix available
    Packages

    dompdf/dompdf

    Summary

    Dompdf allows remote file inclusion because URI validation failure does not halt font registration

    Published
    26 Sept 2022
    DLA-3120-1
    Fix available
    Packages

    poppler

    Summary

    poppler - security update

    Published
    26 Sept 2022
    CVE-2022-41352
    No fix available
    Packages

    , , ,

    Summary

    Published
    26 Sept 2022
    ALSA-2022:6700
    Fix available
    Packages

    firefox

    Summary

    Important: firefox security update

    Published
    26 Sept 2022
    ALSA-2022:6702
    Fix available
    Packages

    firefox

    Summary

    Important: firefox security update

    Published
    26 Sept 2022
    ALSA-2022:6708
    Fix available
    Packages

    thunderbird

    Summary

    Important: thunderbird security update

    Published
    26 Sept 2022
    ALSA-2022:6717
    Fix available
    Packages

    thunderbird

    Summary

    Important: thunderbird security update

    Published
    26 Sept 2022
    DLA-3121-1
    Fix available
    Packages

    firefox-esr

    Summary

    firefox-esr - security update

    Published
    26 Sept 2022
    Packages

    vim, vim, vim

    Summary

    Published
    25 Sept 2022
    AZL-11035
    Fix available
    Packages

    vim

    Summary

    CVE-2022-3297 affecting package vim for versions less than 9.0.0614-1

    Published
    25 Sept 2022
    Packages

    vim, vim, vim, vim, vim

    Summary

    Published
    25 Sept 2022
    BELL-CVE-2022-3297
    No fix available
    Packages

    Summary

    CVE-2022-3297 does not affect BellSoft software

    Published
    25 Sept 2022
    Packages

    vim, vim, vim

    Summary

    Published
    25 Sept 2022
    AZL-11034
    Fix available
    Packages

    vim

    Summary

    CVE-2022-3296 affecting package vim for versions less than 9.0.0614-1

    Published
    25 Sept 2022
    UBUNTU-CVE-2022-3296
    No fix available
    Packages

    vim, vim, vim, vim, vim

    Summary

    Published
    25 Sept 2022
    BELL-CVE-2022-3296
    No fix available
    Packages

    Summary

    CVE-2022-3296 does not affect BellSoft software

    Published
    25 Sept 2022
    SUSE-SU-2022:3379-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP5_Update_35

    Summary

    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP5)

    Published
    25 Sept 2022
    SUSE-SU-2022:3377-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP5_Update_34, kernel-livepatch-SLE15-SP3_Update_22

    Summary

    Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP3)

    Published
    25 Sept 2022
    SUSE-SU-2022:3373-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP4_Update_26

    Summary

    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP4)

    Published
    25 Sept 2022
    SUSE-SU-2022:3372-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP4_Update_28

    Summary

    Security update for the Linux Kernel (Live Patch 28 for SLE 12 SP4)

    Published
    25 Sept 2022
    OSV-2022-953
    Fix available
    Packages

    mongoose

    Summary

    Dynamic-stack-buffer-overflow in rx_icmp

    Published
    25 Sept 2022
    OSV-2022-952
    Fix available
    Packages

    file

    Summary

    UNKNOWN WRITE in regcomp

    Published
    25 Sept 2022
    GHSA-m69r-9g56-7mv8
    Fix available
    Packages

    github.com/hashicorp/consul, github.com/hashicorp/consul, github.com/hashicorp/consul

    Summary

    HashiCorp Consul vulnerable to authorization bypass

    Published
    25 Sept 2022
    GHSA-c429-5p7v-vgjp
    Fix available
    Packages

    @hapi/hoek, @hapi/hoek, hoek

    Summary

    hoek subject to prototype pollution via the clone function.

    Published
    25 Sept 2022
    GHSA-c5fp-x2h5-vjv7
    Fix available
    Packages

    org.apache.pulsar:pulsar-client, org.apache.pulsar:pulsar-client, org.apache.pulsar:pulsar-client, org.apache.pulsar:pulsar-client

    Summary

    Apache Pulsar Java Client vulnerable to Improper Certificate Validation

    Published
    25 Sept 2022
    GHSA-j3q4-gmj4-mj95
    Fix available
    Packages

    rdiffweb

    Summary

    rdiffweb vulnerable to account access via session fixation

    Published
    25 Sept 2022
    GHSA-j3qw-g67q-7m64
    Fix available
    Packages

    org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy

    Summary

    Apache Pulsar Brokers and Proxies vulnerable to Improper Certificate Validation

    Published
    25 Sept 2022
    GHSA-jvf3-mfxv-jcqr
    Fix available
    Packages

    org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy

    Summary

    Apache Pulsar Broker, Proxy, and WebSocket Proxy vulnerable to Improper Certificate Validation

    Published
    25 Sept 2022
    GHSA-9w7j-q3xw-p9vh
    Fix available
    Packages

    github.com/hyperledger/fabric

    Summary

    Hyperledger Fabric subject to Denial of Service via non-validated request

    Published
    25 Sept 2022
    GHSA-qj9p-jvmw-82rh
    Fix available
    Packages

    org.apache.pinot:pinot

    Summary

    Apache Pinot has Groovy Function support enabled by default

    Published
    25 Sept 2022
    GHSA-m7w4-q5vg-5xfp
    Fix available
    Packages

    github.com/mattermost/mattermost-server/v6

    Summary

    Mattermost subject to Denial of Service via upload of special GIF

    Published
    25 Sept 2022
    GHSA-8qv5-68g4-248j
    Fix available
    Packages

    org.scala-lang:scala-library

    Summary

    Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization

    Published
    25 Sept 2022
    GHSA-3mg9-m3f6-v7fq
    Fix available
    Packages

    org.apache.pulsar:pulsar, org.apache.pulsar:pulsar, org.apache.pulsar:pulsar

    Summary

    Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint

    Published
    25 Sept 2022
    GHSA-hr3v-8cp3-68rf
    Fix available
    Packages

    github.com/hashicorp/consul, github.com/hashicorp/consul, github.com/hashicorp/consul

    Summary

    HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

    Published
    25 Sept 2022
    GHSA-42hx-vrxx-5r6v
    No fix available
    Packages

    jodit

    Summary

    Jodit Editor vulnerable to Cross-site Scripting

    Published
    25 Sept 2022
    GHSA-hhxh-qphc-v423
    No fix available
    Packages

    com.nepxion:discovery

    Summary

    Nepxion Discovery vulnerable to potential Information Disclosure due to Server-Side Request Forgery

    Published
    25 Sept 2022
    GHSA-q3f4-9h4p-vgr3
    Fix available
    Packages

    @lionello/secp256k1-js

    Summary

    secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery

    Published
    25 Sept 2022
    GHSA-q979-9m39-23mq
    No fix available
    Packages

    com.nepxion:discovery

    Summary

    Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code Execution

    Published
    25 Sept 2022
    CVE-2022-3297
    Fix available
    Packages

    Summary

    Use After Free in vim/vim

    Published
    25 Sept 2022
    DLA-3119-1
    Fix available
    Packages

    expat

    Summary

    expat - security update

    Published
    25 Sept 2022
    CVE-2022-41343
    Fix available
    Packages

    Summary

    Published
    25 Sept 2022
    CVE-2022-3296
    Fix available
    Packages

    Summary

    Stack-based Buffer Overflow in vim/vim

    Published
    25 Sept 2022
    SUSE-SU-2022:3370-1
    Fix available
    Packages

    kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kernel-livepatch-SLE15-SP4_Update_0

    Summary

    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP4)

    Published
    24 Sept 2022
    SUSE-SU-2022:3369-1
    Fix available
    Packages

    kernel-livepatch-SLE15-SP3_Update_20

    Summary

    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP3)

    Published
    24 Sept 2022
    CVE-2022-41340
    Fix available
    Packages

    Summary

    Published
    24 Sept 2022