Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    Packages

    redis, redis, redis

    Summary

    Published
    23 Sept 2022
    Packages

    redis, redis, redis, redis

    Summary

    Published
    23 Sept 2022
    Packages

    redis

    Summary

    Published
    23 Sept 2022
    Packages

    virtualbox, virtualbox-kmp

    Summary

    Security update for virtualbox

    Published
    23 Sept 2022
    CVE-2022-37235
    No fix available
    Packages

    Summary

    Published
    23 Sept 2022
    CVE-2022-37232
    No fix available
    Packages

    Summary

    Published
    23 Sept 2022
    CVE-2021-41803
    Fix available
    Packages

    Summary

    Published
    23 Sept 2022
    DEBIAN-CVE-2021-41803
    No fix available
    Packages

    consul

    Summary

    Published
    23 Sept 2022
    UBUNTU-CVE-2021-41803
    No fix available
    Packages

    consul, consul, consul

    Summary

    Published
    23 Sept 2022
    CVE-2022-40298
    No fix available
    Packages

    Summary

    Published
    23 Sept 2022
    CVE-2022-38573
    No fix available
    Packages

    Summary

    Published
    23 Sept 2022
    CVE-2022-30426
    No fix available
    Packages

    Summary

    Published
    23 Sept 2022
    OSV-2022-937
    No fix available
    Packages

    mongoose

    Summary

    Use-after-poison in rx_ip

    Published
    23 Sept 2022
    OSV-2022-934
    Fix available
    Packages

    kimageformats

    Summary

    Index-out-of-bounds in LibRaw::parse_tiff_ifd

    Published
    23 Sept 2022
    GHSA-5j86-vmpx-42pc
    Fix available
    Packages

    com.liferay:com.liferay.headless.discovery.web

    Summary

    Liferay Portal Path Traversal Vulnerability via the Hypermedia REST APIs Module

    Published
    23 Sept 2022
    GHSA-7cgv-v83v-rr87
    Fix available
    Packages

    github.com/hashicorp/vault, github.com/hashicorp/vault, github.com/hashicorp/vault

    Summary

    HashiCorp Vault vulnerable to incorrect metadata access

    Published
    23 Sept 2022
    GHSA-7m65-hmvg-rxpc
    Fix available
    Packages

    com.liferay:com.liferay.site.memberships.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Vulnerable to XSS in the Site Module

    Published
    23 Sept 2022
    GHSA-7r3w-wggm-pjwf
    Fix available
    Packages

    com.liferay:com.liferay.portal.search.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Vulnerable to XSS in the Portal Search Module

    Published
    23 Sept 2022
    GHSA-83qx-288m-72w4
    Fix available
    Packages

    com.liferay.portal:release.portal.bom

    Summary

    Liferay Portal Missing Authorization vulnerability

    Published
    23 Sept 2022
    GHSA-8mp9-w7gr-pvj3
    Fix available
    Packages

    com.liferay:com.liferay.fragment.renderer.collection.filter.impl, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Vulnerable to XSS via the filter_ Prefix

    Published
    23 Sept 2022
    GHSA-h9ww-wjg4-jvvg
    Fix available
    Packages

    com.liferay:com.liferay.translation.web, com.liferay.portal:release.dxp.bom

    Summary

    Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module

    Published
    23 Sept 2022
    GHSA-jq8c-j47c-vvwm
    No fix available
    Packages

    soap:soap

    Summary

    Apache SOAP's RPCRouterServlet allows reading of arbitrary files over HTTP

    Published
    23 Sept 2022
    GHSA-w397-9p2j-6x23
    Fix available
    Packages

    com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.dxp.bom, com.liferay.portal:com.liferay.util.java

    Summary

    Liferay Portal and Liferay DXP HtmlUtil.escapeRedirect Can Be Circumvented

    Published
    23 Sept 2022
    GHSA-wffm-j7m8-93g4
    Fix available
    Packages

    com.liferay:com.liferay.asset.taglib

    Summary

    Liferay Portal and Liferay DXP Vulnerable to XSS via Tag Name

    Published
    23 Sept 2022
    GHSA-h4qg-p7r2-cpg3
    Fix available
    Packages

    org.apache.xmlgraphics:batik

    Summary

    Apache Batik vulnerable to Server-Side Request Forgery

    Published
    23 Sept 2022
    GHSA-53jm-3hc9-fqqc
    Fix available
    Packages

    org.apache.xmlgraphics:batik, org.apache.xmlgraphics:batik-bridge

    Summary

    Apache Batik vulnerable to Server-Side Request Forgery

    Published
    23 Sept 2022
    GHSA-c5xv-qc8p-mh2v
    Fix available
    Packages

    org.apache.xmlgraphics:batik, org.apache.xmlgraphics:batik-bridge

    Summary

    Apache Batik Server-Side Request Forgery

    Published
    23 Sept 2022
    GHSA-fvf5-xp83-vrqp
    No fix available
    Packages

    icecoder/icecoder

    Summary

    ICEcoder vulnerable to Path Traversal

    Published
    23 Sept 2022
    GHSA-gmj8-84r4-h46j
    Fix available
    Packages

    rdiffweb

    Summary

    rdiffweb Cross-Site Request Forgery vulnerability can lead to user email ID being changed

    Published
    23 Sept 2022
    GHSA-74j6-3hh4-w3f5
    Fix available
    Packages

    rdiffweb

    Summary

    rdiffweb Cross-Site Request Forgery vulnerability

    Published
    23 Sept 2022
    GHSA-9rwj-9j2h-fhvm
    Fix available
    Packages

    tui-grid

    Summary

    Toast UI Grid vulnerable to Cross-site Scripting

    Published
    23 Sept 2022
    OSV-2022-932
    No fix available
    Packages

    openvpn

    Summary

    Stack-buffer-overflow in ntlm_phase_3

    Published
    23 Sept 2022
    OSV-2022-931
    No fix available
    Packages

    file

    Summary

    Heap-buffer-overflow in file_magwarn

    Published
    23 Sept 2022
    CVE-2022-40188
    Fix available
    Packages

    Summary

    Published
    23 Sept 2022
    DSA-5237-1
    Fix available
    Packages

    firefox-esr

    Summary

    firefox-esr - security update

    Published
    23 Sept 2022
    CVE-2022-36944
    Fix available
    Packages

    Summary

    Published
    23 Sept 2022
    CVE-2022-35951
    Fix available
    Packages

    Summary

    Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow

    Published
    23 Sept 2022
    CVE-2022-35252
    Fix available
    Packages

    Summary

    Published
    23 Sept 2022
    CVE-2022-3278
    Fix available
    Packages

    Summary

    NULL Pointer Dereference in vim/vim

    Published
    23 Sept 2022
    Packages

    squid3, squid3, squid, squid

    Summary

    Published
    23 Sept 2022
    Packages

    squid, squid

    Summary

    Published
    23 Sept 2022
    CVE-2022-40716
    Fix available
    Packages

    Summary

    Published
    23 Sept 2022
    GHSA-5rp4-749p-vx26
    Fix available
    Packages

    apache-airflow

    Summary

    Apache Airflow vulnerable to Use of Externally-Controlled Format String

    Published
    22 Sept 2022
    GHSA-4fg5-j4mm-wfpg
    Fix available
    Packages

    apache-airflow

    Summary

    Apache Airflow contains open redirect

    Published
    22 Sept 2022
    CVE-2022-40089
    No fix available
    Packages

    Summary

    Published
    22 Sept 2022
    CVE-2022-40088
    No fix available
    Packages

    Summary

    Published
    22 Sept 2022
    CVE-2022-40087
    No fix available
    Packages

    Summary

    Published
    22 Sept 2022
    CVE-2022-36934
    No fix available
    Packages

    Summary

    Published
    22 Sept 2022
    CVE-2022-31937
    No fix available
    Packages

    Summary

    Published
    22 Sept 2022
    CVE-2022-23458
    Fix available
    Packages

    Summary

    Toast UI Grid vulnerable to Cross-site scripting

    Published
    22 Sept 2022