Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2022-2471
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-3211
    Fix available
    Packages

    Summary

    Cross-site Scripting (XSS) - Stored in pimcore/pimcore

    Published
    15 Sept 2022
    SUSE-SU-2022:3283-1
    Fix available
    Packages

    libgit2, libgit2

    Summary

    Security update for libgit2

    Published
    15 Sept 2022
    SUSE-SU-2022:3282-1
    Fix available
    Packages

    kernel-azure, kernel-source-azure, kernel-syms-azure, kernel-azure, kernel-source-azure, kernel-syms-azure

    Summary

    Security update for the Linux Kernel

    Published
    15 Sept 2022
    SUSE-SU-2022:3281-1
    Fix available
    Packages

    MozillaThunderbird, MozillaThunderbird, MozillaThunderbird, MozillaThunderbird, MozillaThunderbird, MozillaThunderbird

    Summary

    Security update for MozillaThunderbird

    Published
    15 Sept 2022
    CVE-2021-44076
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-37257
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-37266
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-38789
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-38788
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    Packages

    opera

    Summary

    Security update for opera

    Published
    15 Sept 2022
    CVE-2022-3224
    Fix available
    Packages

    Summary

    Misinterpretation of Input in ionicabizau/parse-url

    Published
    15 Sept 2022
    USN-5613-1
    Fix available
    Packages

    vim, vim, vim, vim

    Summary

    vim vulnerabilities

    Published
    15 Sept 2022
    Packages

    gpac

    Summary

    Published
    15 Sept 2022
    PYSEC-2022-278
    Fix available
    Packages

    rdiffweb

    Summary

    Published
    15 Sept 2022
    UBUNTU-CVE-2022-3222
    No fix available
    Packages

    gpac, gpac, gpac, gpac, gpac, gpac

    Summary

    Published
    15 Sept 2022
    CVE-2022-3221
    Fix available
    Packages

    Summary

    Cross-Site Request Forgery (CSRF) in ikus060/rdiffweb

    Published
    15 Sept 2022
    RLSA-2022:6542
    Fix available
    Packages

    libzip, libzip, php, php-pear, php-pear, php-pecl-apcu, php-pecl-apcu, php-pecl-rrd, php-pecl-xdebug, php-pecl-zip, php-pecl-zip

    Summary

    Moderate: php:7.4 security update

    Published
    15 Sept 2022
    RLSA-2022:6540
    Fix available
    Packages

    webkit2gtk3

    Summary

    Moderate: webkit2gtk3 security update

    Published
    15 Sept 2022
    RLSA-2022:6539
    Fix available
    Packages

    dotnet6.0

    Summary

    Moderate: .NET 6.0 security and bugfix update

    Published
    15 Sept 2022
    CVE-2022-31735
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    UBUNTU-CVE-2022-40738
    No fix available
    Packages

    kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive

    Summary

    Published
    15 Sept 2022
    UBUNTU-CVE-2022-40737
    No fix available
    Packages

    kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive

    Summary

    Published
    15 Sept 2022
    UBUNTU-CVE-2022-40736
    No fix available
    Packages

    kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive, kodi-inputstream-adaptive

    Summary

    Published
    15 Sept 2022
    SUSE-RU-2022:3275-1
    Fix available
    Packages

    python-aiohttp, python-typing_extensions, python-aiohttp, python-typing_extensions, python-aiohttp, python-typing_extensions, python-aiohttp, python-typing_extensions, python-aiohttp, python-aiohttp, python-typing_extensions

    Summary

    Recommended update for python-aiohttp, python-typing_extensions

    Published
    15 Sept 2022
    GHSA-fph9-f5r6-vhqf
    Fix available
    Packages

    org.eclipse.milo:sdk-server

    Summary

    Eclipse Milo vulnerable to Resource Exhaustion (Denial of Service)

    Published
    15 Sept 2022
    GHSA-r7vq-6425-j94w
    Fix available
    Packages

    tuf

    Summary

    Python-TUF vulnerable to incorrect threshold signature computation for new root metadata

    Published
    15 Sept 2022
    GHSA-ggf6-638m-vqmg
    Fix available
    Packages

    github.com/gravitl/netmaker

    Summary

    Netmaker vulnerable to Insufficient Granularity of Access Control

    Published
    15 Sept 2022
    GHSA-pfw4-xjgm-267c
    Fix available
    Packages

    github.com/matrix-org/dendrite

    Summary

    Dendrite signature checks not applied to some retrieved missing events

    Published
    15 Sept 2022
    GHSA-gqqf-g5r7-84vf
    Fix available
    Packages

    typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core, typo3/cms-core

    Summary

    TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection

    Published
    15 Sept 2022
    GHSA-cq7q-5c67-w39w
    Fix available
    Packages

    matrix-appservice-irc

    Summary

    matrix-appservice-irc vulnerable to IRC mode parameter confusion

    Published
    15 Sept 2022
    GHSA-xvqg-mv25-rwvw
    Fix available
    Packages

    matrix-appservice-irc

    Summary

    Parsing issue in matrix-org/node-irc leading to room takeovers

    Published
    15 Sept 2022
    GHSA-r8m2-4x37-6592
    Fix available
    Packages

    Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.osx-arm64, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-x86

    Summary

    .NET Denial of Service Vulnerability

    Published
    15 Sept 2022
    GHSA-m77f-652q-wwp4
    Fix available
    Packages

    axum-core, axum-core

    Summary

    axum-core has no default limit put on request bodies

    Published
    15 Sept 2022
    CVE-2022-40738
    Fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-40736
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-40737
    Fix available
    Packages

    Summary

    Published
    15 Sept 2022
    GHSA-qcqv-38jg-2r43
    Fix available
    Packages

    pageflow, pageflow

    Summary

    Pageflow vulnerable to insecure direct object reference in membership update endpoint

    Published
    15 Sept 2022
    GHSA-wrrw-crp8-979q
    Fix available
    Packages

    pageflow, pageflow

    Summary

    Pageflow vulnerable to sensitive user data extraction via Ransack query injection

    Published
    15 Sept 2022
    GHSA-qv98-3369-g364
    Fix available
    Packages

    kubevirt.io/kubevirt

    Summary

    KubeVirt vulnerable to arbitrary file read on host

    Published
    15 Sept 2022
    USN-5612-1
    Fix available
    Packages

    intel-microcode, intel-microcode, intel-microcode

    Summary

    intel-microcode vulnerability

    Published
    15 Sept 2022
    CVE-2022-38595
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-38594
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-38323
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2022-38352
    No fix available
    Packages

    Summary

    Published
    15 Sept 2022
    CVE-2018-25047
    Fix available
    Packages

    Summary

    Published
    15 Sept 2022
    Packages

    smarty3, smarty3, smarty3, smarty4, smarty4, smarty4

    Summary

    Published
    15 Sept 2022
    Packages

    smarty3, smarty3, smarty3, smarty3, smarty3, smarty3, smarty3

    Summary

    Published
    15 Sept 2022
    OSV-2022-896
    No fix available
    Packages

    libsass

    Summary

    Segv on unknown address in Sass::unifyComplex

    Published
    15 Sept 2022
    GHSA-j9fq-vwqv-2fm2
    Fix available
    Packages

    parse-url

    Summary

    Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url

    Published
    15 Sept 2022