Open Source Vulnerabilities
Kernel
ipv6: fix panic when forwarding a pkt with no in6 dev
Kernel
ipv6: fix panic when forwarding a pkt with no in6 dev
Kernel
ep93xx: clock: Fix UAF in ep93xx_clk_register_gate()
Kernel
ep93xx: clock: Fix UAF in ep93xx_clk_register_gate()
Kernel
ARM: davinci: da850-evm: Avoid NULL pointer dereference
Kernel
ARM: davinci: da850-evm: Avoid NULL pointer dereference
Kernel
i2c: dev: check return value when calling dev_set_name()
Kernel
i2c: dev: check return value when calling dev_set_name()
Kernel
ALSA: pcm: Test for "silence" field in struct "pcm_format_data"
Kernel
ALSA: pcm: Test for "silence" field in struct "pcm_format_data"
Kernel
dm integrity: fix memory corruption when tag_size is less than digest size
Kernel
dm integrity: fix memory corruption when tag_size is less than digest size
Kernel
ax25: Fix UAF bugs in ax25 timers
kernel-livepatch-SLE15-SP2_Update_24, kernel-livepatch-SLE15-SP2_Update_22, kernel-livepatch-SLE15-SP2_Update_24, kernel-livepatch-SLE15-SP2_Update_22, kernel-livepatch-SLE15-SP3_Update_5, kernel-livepatch-SLE15-SP3_Update_14, kernel-livepatch-SLE15-SP3_Update_10, kernel-livepatch-SLE15-SP3_Update_7, kernel-livepatch-SLE15-SP3_Update_5, kernel-livepatch-SLE15-SP3_Update_14, kernel-livepatch-SLE15-SP3_Update_10, kernel-livepatch-SLE15-SP3_Update_7, kernel-livepatch-SLE15-SP3_Update_5, kernel-livepatch-SLE15-SP3_Update_14, kernel-livepatch-SLE15-SP3_Update_10, kernel-livepatch-SLE15-SP3_Update_7, kernel-livepatch-SLE15-SP3_Update_5, kernel-livepatch-SLE15-SP3_Update_14, kernel-livepatch-SLE15-SP3_Update_10, kernel-livepatch-SLE15-SP3_Update_7
Security update for the Linux Kernel (Live Patch 7 for SLE 15 SP3)
kernel-livepatch-SLE15-SP2_Update_24/ kernel-livepatch-SLE15-SP2_Update_22/ kernel-livepatch-SLE15-SP2_Update_24/ kernel-livepatch-SLE15-SP2_Update_22/ kernel-livepatch-SLE15-SP3_Update_5/ kernel-livepatch-SLE15-SP3_Update_14/ kernel-livepatch-SLE15-SP3_Update_10/ kernel-livepatch-SLE15-SP3_Update_7/ kernel-livepatch-SLE15-SP3_Update_5/ kernel-livepatch-SLE15-SP3_Update_14/ kernel-livepatch-SLE15-SP3_Update_10/ kernel-livepatch-SLE15-SP3_Update_7/ kernel-livepatch-SLE15-SP3_Update_5/ kernel-livepatch-SLE15-SP3_Update_14/ kernel-livepatch-SLE15-SP3_Update_10/ kernel-livepatch-SLE15-SP3_Update_7/ kernel-livepatch-SLE15-SP3_Update_5/ kernel-livepatch-SLE15-SP3_Update_14/ kernel-livepatch-SLE15-SP3_Update_10/ kernel-livepatch-SLE15-SP3_Update_7
Security update for the Linux Kernel (Live Patch 7 for SLE 15 SP3)
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in snipe/snipe-it
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in snipe/snipe-it
rusoto_credential
Rusoto is unmaintained
librecad
Updated librecad packages fix security vulnerability
libdxfrw
Updated libdxfrw packages fix security vulnerability
radare2, radare2, radare2, radare2, radare2, radare2
kgraft-patch-SLE12-SP5_Update_20, kgraft-patch-SLE12-SP5_Update_22, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_20, kgraft-patch-SLE12-SP5_Update_22, kgraft-patch-SLE12-SP5_Update_23, kgraft-patch-SLE12-SP5_Update_20, kgraft-patch-SLE12-SP5_Update_22, kgraft-patch-SLE12-SP5_Update_23
Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP5)
kgraft-patch-SLE12-SP5_Update_20/ kgraft-patch-SLE12-SP5_Update_22/ kgraft-patch-SLE12-SP5_Update_23/ kgraft-patch-SLE12-SP5_Update_20/ kgraft-patch-SLE12-SP5_Update_22/ kgraft-patch-SLE12-SP5_Update_23/ kgraft-patch-SLE12-SP5_Update_20/ kgraft-patch-SLE12-SP5_Update_22/ kgraft-patch-SLE12-SP5_Update_23
Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP5)
heap-use-after-free in radareorg/radare2
kgraft-patch-SLE12-SP4_Update_20
Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP4)
kgraft-patch-SLE12-SP4_Update_20
Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP4)
libinput
Updated libinput packages fix security vulnerability
gzip, xz
Updated gzip/xz packages fix security vulnerability
kgraft-patch-SLE12-SP4_Update_22
Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP4)
kgraft-patch-SLE12-SP4_Update_22
Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP4)
prestashop/prestashop
PrestaShop XSS Vulnerability
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Hash collision attack vulnerability in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Hash collision attack vulnerability in Jenkins
org.jboss.as:jboss-as-server
JBoss AS may expose root content if excluded-contexts list is mismatched
org.jboss.as:jboss-as-server
JBoss AS may expose root content if excluded-contexts list is mismatched
nokogiri
Nokogiri is vulnerable to XML External Entity (XXE) attack
nokogiri
Nokogiri is vulnerable to XML External Entity (XXE) attack
roundup
Multiple cross-site scripting (XSS) vulnerabilities in Roundup
roundup
Multiple cross-site scripting (XSS) vulnerabilities in Roundup
contao/core
Contao core SQL Injection Vulnerability
org.apache.struts:struts2-core
Unrestricted Upload of File with Dangerous Type in Apache Struts2
org.apache.struts:struts2-core
Unrestricted Upload of File with Dangerous Type in Apache Struts2
trytond
trytond Incorrect Authorization vulnerability
passenger
RubyGems passenger gem allows remote attackers to delete files
passenger
RubyGems passenger gem allows remote attackers to delete files
org.jenkins-ci.plugins:ci-game
Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)
org.jenkins-ci.plugins:ci-game
Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)
org.jenkins-ci.plugins:violations
Jenkins Violation Plugin allows Cross-Site Scripting (XSS)
org.jenkins-ci.plugins:violations
Jenkins Violation Plugin allows Cross-Site Scripting (XSS)
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Jenkins allows Cross-Site Scripting (XSS) via Crafted URL
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Jenkins allows Cross-Site Scripting (XSS) via Crafted URL
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle included private user files in course backups
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle included private user files in course backups
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle default permissions too permissive
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle default permissions too permissive
moodle/moodle, moodle/moodle, moodle/moodle
Moodle backs up private files
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle backs up private files
tahoe-lafs
Tahoe-LAFS fails to ensure integrity
org.apache.hadoop:hadoop-main
Hadoop symlink vulnerability
org.apache.hadoop:hadoop-main
Hadoop symlink vulnerability
mruby, mruby, mruby, mruby, mruby, mruby, mruby
org.owasp.antisamy:antisamy
Cross-site Scripting in OWASP AntiSamy
org.owasp.antisamy:antisamy
Cross-site Scripting in OWASP AntiSamy
net.sourceforge.htmlunit:neko-htmlunit
Denial of service in HtmlUnit-Neko
net.sourceforge.htmlunit:neko-htmlunit
Denial of service in HtmlUnit-Neko
org.owasp.antisamy:antisamy
Cross-site Scripting in OWASP AntiSamy
org.owasp.antisamy:antisamy
Cross-site Scripting in OWASP AntiSamy
github.com/kardianos/service
Disputed: OS Command injection in github.com/kardianos/service
github.com/kardianos/service
Disputed: OS Command injection in github.com/kardianos/service
pimcore/pimcore
SQL Injection found in Pimcore
microweber/microweber
Cross-site Scripting in Microweber
net.mingsoft:ms-mcms
Cross Site Request Forgery in Mingsoft MCMS
net.mingsoft:ms-mcms
Cross Site Request Forgery in Mingsoft MCMS
git-interface
Command injection in git-interface
libexif
Heap-buffer-overflow in exif_get_long
libjxl
Segv on unknown address in jxl::N_SSE4::WriteToU8Stage::ProcessRow
libjxl
Segv on unknown address in jxl::N_SSE4::WriteToU8Stage::ProcessRow
Out-of-bounds Read in mrb_obj_is_kind_of in in mruby/mruby
