Open Source Vulnerabilities
joblib, joblib, joblib, joblib, joblib
lcms
Use-of-uninitialized-value in FileWrite
dompdf/dompdf
Dompdf allows remote file inclusion because URI validation failure does not halt font registration
dompdf/dompdf
Dompdf allows remote file inclusion because URI validation failure does not halt font registration
firefox
Important: firefox security update
firefox
Important: firefox security update
thunderbird
Important: thunderbird security update
thunderbird
Important: thunderbird security update
vim
CVE-2022-3297 affecting package vim for versions less than 9.0.0614-1
vim
CVE-2022-3297 affecting package vim for versions less than 9.0.0614-1
CVE-2022-3297 does not affect BellSoft software
vim
CVE-2022-3296 affecting package vim for versions less than 9.0.0614-1
vim
CVE-2022-3296 affecting package vim for versions less than 9.0.0614-1
CVE-2022-3296 does not affect BellSoft software
kgraft-patch-SLE12-SP5_Update_35
Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP5)
kgraft-patch-SLE12-SP5_Update_35
Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP5)
kgraft-patch-SLE12-SP5_Update_34, kernel-livepatch-SLE15-SP3_Update_22
Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP3)
kgraft-patch-SLE12-SP5_Update_34/ kernel-livepatch-SLE15-SP3_Update_22
Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP3)
kgraft-patch-SLE12-SP4_Update_26
Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP4)
kgraft-patch-SLE12-SP4_Update_26
Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP4)
kgraft-patch-SLE12-SP4_Update_28
Security update for the Linux Kernel (Live Patch 28 for SLE 12 SP4)
kgraft-patch-SLE12-SP4_Update_28
Security update for the Linux Kernel (Live Patch 28 for SLE 12 SP4)
mongoose
Dynamic-stack-buffer-overflow in rx_icmp
github.com/hashicorp/consul, github.com/hashicorp/consul, github.com/hashicorp/consul
HashiCorp Consul vulnerable to authorization bypass
github.com/hashicorp/consul/ github.com/hashicorp/consul/ github.com/hashicorp/consul
HashiCorp Consul vulnerable to authorization bypass
@hapi/hoek, @hapi/hoek, hoek
hoek subject to prototype pollution via the clone function.
@hapi/hoek/ @hapi/hoek/ hoek
hoek subject to prototype pollution via the clone function.
org.apache.pulsar:pulsar-client, org.apache.pulsar:pulsar-client, org.apache.pulsar:pulsar-client, org.apache.pulsar:pulsar-client
Apache Pulsar Java Client vulnerable to Improper Certificate Validation
org.apache.pulsar:pulsar-client/ org.apache.pulsar:pulsar-client/ org.apache.pulsar:pulsar-client/ org.apache.pulsar:pulsar-client
Apache Pulsar Java Client vulnerable to Improper Certificate Validation
rdiffweb
rdiffweb vulnerable to account access via session fixation
rdiffweb
rdiffweb vulnerable to account access via session fixation
org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy
Apache Pulsar Brokers and Proxies vulnerable to Improper Certificate Validation
org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy/ org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy/ org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy/ org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy
Apache Pulsar Brokers and Proxies vulnerable to Improper Certificate Validation
org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy, org.apache.pulsar:pulsar-broker, org.apache.pulsar:pulsar-proxy
Apache Pulsar Broker, Proxy, and WebSocket Proxy vulnerable to Improper Certificate Validation
org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy/ org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy/ org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy/ org.apache.pulsar:pulsar-broker/ org.apache.pulsar:pulsar-proxy
Apache Pulsar Broker, Proxy, and WebSocket Proxy vulnerable to Improper Certificate Validation
github.com/hyperledger/fabric
Hyperledger Fabric subject to Denial of Service via non-validated request
github.com/hyperledger/fabric
Hyperledger Fabric subject to Denial of Service via non-validated request
org.apache.pinot:pinot
Apache Pinot has Groovy Function support enabled by default
org.apache.pinot:pinot
Apache Pinot has Groovy Function support enabled by default
github.com/mattermost/mattermost-server/v6
Mattermost subject to Denial of Service via upload of special GIF
github.com/mattermost/mattermost-server/v6
Mattermost subject to Denial of Service via upload of special GIF
org.scala-lang:scala-library
Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization
org.scala-lang:scala-library
Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization
org.apache.pulsar:pulsar, org.apache.pulsar:pulsar, org.apache.pulsar:pulsar
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
org.apache.pulsar:pulsar/ org.apache.pulsar:pulsar/ org.apache.pulsar:pulsar
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
github.com/hashicorp/consul, github.com/hashicorp/consul, github.com/hashicorp/consul
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
github.com/hashicorp/consul/ github.com/hashicorp/consul/ github.com/hashicorp/consul
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
jodit
Jodit Editor vulnerable to Cross-site Scripting
com.nepxion:discovery
Nepxion Discovery vulnerable to potential Information Disclosure due to Server-Side Request Forgery
com.nepxion:discovery
Nepxion Discovery vulnerable to potential Information Disclosure due to Server-Side Request Forgery
@lionello/secp256k1-js
secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery
@lionello/secp256k1-js
secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery
com.nepxion:discovery
Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code Execution
com.nepxion:discovery
Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code Execution
Stack-based Buffer Overflow in vim/vim
kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_26, kgraft-patch-SLE12-SP5_Update_27, kgraft-patch-SLE12-SP5_Update_30, kernel-livepatch-SLE15-SP4_Update_0
Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP4)
kgraft-patch-SLE12-SP5_Update_23/ kgraft-patch-SLE12-SP5_Update_26/ kgraft-patch-SLE12-SP5_Update_27/ kgraft-patch-SLE12-SP5_Update_30/ kgraft-patch-SLE12-SP5_Update_23/ kgraft-patch-SLE12-SP5_Update_26/ kgraft-patch-SLE12-SP5_Update_27/ kgraft-patch-SLE12-SP5_Update_30/ kgraft-patch-SLE12-SP5_Update_23/ kgraft-patch-SLE12-SP5_Update_26/ kgraft-patch-SLE12-SP5_Update_27/ kgraft-patch-SLE12-SP5_Update_30/ kgraft-patch-SLE12-SP5_Update_23/ kgraft-patch-SLE12-SP5_Update_26/ kgraft-patch-SLE12-SP5_Update_27/ kgraft-patch-SLE12-SP5_Update_30/ kernel-livepatch-SLE15-SP4_Update_0
Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP4)
kernel-livepatch-SLE15-SP3_Update_20
Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP3)
kernel-livepatch-SLE15-SP3_Update_20
Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP3)
