Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    PYSEC-2022-205
    Fix available
    Packages

    waitress

    Summary

    Published
    31 May 2022
    CVE-2022-31015
    Fix available
    Packages

    Summary

    Uncaught Exception (due to a data race) leads to process termination in Waitress

    Published
    31 May 2022
    CVE-2022-31013
    Fix available
    Packages

    Summary

    Authentication bypass in Vartalap chat-server

    Published
    31 May 2022
    CVE-2022-1947
    Fix available
    Packages

    Summary

    Use of Incorrect Operator in polonel/trudesk

    Published
    31 May 2022
    CVE-2022-1808
    Fix available
    Packages

    Summary

    Execution with Unnecessary Privileges in polonel/trudesk

    Published
    31 May 2022
    CVE-2022-1893
    Fix available
    Packages

    Summary

    Improper Removal of Sensitive Information Before Storage or Transfer in polonel/trudesk

    Published
    31 May 2022
    CVE-2022-29648
    No fix available
    Packages

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    USN-5454-2
    Fix available
    Packages

    cups

    Summary

    cups vulnerabilities

    Published
    31 May 2022
    CVE-2022-31005
    Fix available
    Packages

    Summary

    Integer Overflow in Vapor's HTTP Range Request

    Published
    31 May 2022
    CVE-2022-31011
    Fix available
    Packages

    Summary

    TiDB authentication bypass vulnerability

    Published
    31 May 2022
    CVE-2022-31007
    Fix available
    Packages

    Summary

    Privilege escalation from administrator in eLabFTW

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    Packages

    sofia-sip, sofia-sip, sofia-sip, sofia-sip

    Summary

    Published
    31 May 2022
    GSD-2022-30190
    No fix available
    Packages

    Summary

    From the original tweet: Interesting maldoc was submitted from Belarus. It uses Word's external link to load the HTML and then uses the "ms-msdt" scheme to execute PowerShell code. From Microsoft: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. This issue has been nicknamed "Follina "

    Published
    31 May 2022
    USN-5451-1
    Fix available
    Packages

    influxdb, influxdb

    Summary

    influxdb vulnerability

    Published
    31 May 2022
    Packages

    libdxfrw, librecad, libdxfrw, librecad

    Summary

    Security update for librecad

    Published
    31 May 2022
    CVE-2022-29258
    Fix available
    Packages

    Summary

    Cross-site Scripting in Filter Stream Converter Application in XWiki Platform

    Published
    31 May 2022
    CVE-2022-29245
    Fix available
    Packages

    Summary

    Weak private key generation in SSH.NET

    Published
    31 May 2022
    CVE-2022-29243
    Fix available
    Packages

    Summary

    Improper input-size validation on the user new session name in Nextcloud Server

    Published
    31 May 2022
    CVE-2022-22361
    No fix available
    Packages

    Summary

    Published
    31 May 2022
    CVE-2022-29220
    Fix available
    Packages

    Summary

    No verification of commits origin in github-action-merge-dependabot

    Published
    31 May 2022
    SUSE-SU-2022:1898-1
    Fix available
    Packages

    fribidi, fribidi, fribidi

    Summary

    Security update for fribidi

    Published
    31 May 2022
    Packages

    libssl-dev, libssl-doc, libssl1.0.0, openssl

    Summary

    Fix CVE(s): CVE-2022-1473, CVE-2022-1292

    Published
    31 May 2022
    Packages

    platform-python, platform-python-debug, platform-python-devel, python3-devel, python3-idle, python3-libs, python3-test, python3-tkinter

    Summary

    Fixed CVEs in python3: CVE-2022-0391, CVE-2021-4189, CVE-2021-3737

    Published
    31 May 2022
    CVE-2022-23082
    Fix available
    Packages

    Summary

    CureKit - Path Traversal in isFileOutsideDir

    Published
    31 May 2022
    Packages

    vim, vim, vim

    Summary

    Published
    31 May 2022
    BELL-CVE-2022-1942
    No fix available
    Packages

    Summary

    CVE-2022-1942 does not affect BellSoft software

    Published
    31 May 2022
    Packages

    tika, tika, tika, tika, tika, tika, tika

    Summary

    Published
    31 May 2022
    Packages

    vim, vim, vim, vim, vim

    Summary

    Published
    31 May 2022
    CVE-2022-29725
    No fix available
    Packages

    Summary

    Published
    31 May 2022
    CVE-2022-30973
    Fix available
    Packages

    Summary

    Missing fix for CVE-2022-30126 in 1.28.2

    Published
    31 May 2022
    CVE-2022-29712
    No fix available
    Packages

    Summary

    Published
    31 May 2022
    CVE-2022-29711
    Fix available
    Packages

    Summary

    Published
    31 May 2022
    CVE-2022-30034
    Fix available
    Packages

    Summary

    Published
    31 May 2022
    SUSE-SU-2022:1895-1
    Fix available
    Packages

    postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13, postgresql13

    Summary

    Security update for postgresql13

    Published
    31 May 2022
    SUSE-SU-2022:1894-1
    Fix available
    Packages

    postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12, postgresql12

    Summary

    Security update for postgresql12

    Published
    31 May 2022
    SUSE-SU-2022:1616-1
    Fix available
    Packages

    bind, bind, bind, bind, bind, bind, bind

    Summary

    Security update for bind

    Published
    31 May 2022
    USN-5454-1
    Fix available
    Packages

    cups, cups, cups

    Summary

    cups vulnerabilities

    Published
    31 May 2022
    SUSE-SU-2022:1893-1
    Fix available
    Packages

    php74, php74

    Summary

    Security update for php74

    Published
    31 May 2022
    SUSE-SU-2022:1892-1
    Fix available
    Packages

    dpdk, dpdk-thunderx, dpdk, dpdk-thunderx, dpdk, dpdk-thunderx

    Summary

    Security update for dpdk

    Published
    31 May 2022
    SUSE-SU-2022:1891-1
    Fix available
    Packages

    librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp, librelp

    Summary

    Security update for librelp

    Published
    31 May 2022
    CVE-2021-3555
    No fix available
    Packages

    Summary

    Published
    31 May 2022
    SUSE-SU-2022:1890-1
    Fix available
    Packages

    postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10, postgresql10

    Summary

    Security update for postgresql10

    Published
    31 May 2022