Lucene search

K

Charitable Donations & Fundraising Team Security Vulnerabilities

alpinelinux
alpinelinux

CVE-2024-22232

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s...

7.7CVSS

7.4AI Score

0.0004EPSS

2024-06-27 07:15 AM
6
alpinelinux
alpinelinux

CVE-2021-3560

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this...

7.8CVSS

6.6AI Score

0.012EPSS

2022-02-16 07:15 PM
35
alpinelinux
alpinelinux

CVE-2023-20867

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual...

3.9CVSS

5.2AI Score

0.005EPSS

2023-06-13 05:15 PM
16
alpinelinux
alpinelinux

CVE-2023-38180

.NET and Visual Studio Denial of Service...

7.5CVSS

7.9AI Score

0.007EPSS

2023-08-08 07:15 PM
33
alpinelinux
alpinelinux

CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October...

7.5CVSS

8.5AI Score

0.732EPSS

2023-10-10 02:15 PM
28
alpinelinux
alpinelinux

CVE-2024-22231

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt...

5CVSS

6.1AI Score

0.0004EPSS

2024-06-27 07:15 AM
10
alpinelinux
alpinelinux

CVE-2023-5981

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5...

5.9CVSS

7.1AI Score

0.001EPSS

2023-11-28 12:15 PM
13
alpinelinux
alpinelinux

CVE-2023-46838

Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts are directly...

7.5CVSS

7.7AI Score

0.001EPSS

2024-01-29 11:15 AM
10
alpinelinux
alpinelinux

CVE-2024-6292

Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...

6.7AI Score

0.0004EPSS

2024-06-24 10:15 PM
alpinelinux
alpinelinux

CVE-2024-3727

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other...

8.3CVSS

7.9AI Score

0.0004EPSS

2024-05-14 03:42 PM
5
alpinelinux
alpinelinux

CVE-2024-6293

Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...

6.7AI Score

0.0004EPSS

2024-06-24 10:15 PM
2
alpinelinux
alpinelinux

CVE-2024-6291

Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...

6.7AI Score

0.0004EPSS

2024-06-24 10:15 PM
1
alpinelinux
alpinelinux

CVE-2021-35588

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker...

3.1CVSS

4.6AI Score

0.002EPSS

2021-10-20 11:16 AM
14
alpinelinux
alpinelinux

CVE-2024-21404

.NET Denial of Service...

7.5CVSS

7.7AI Score

0.003EPSS

2024-02-13 06:15 PM
3
alpinelinux
alpinelinux

CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count....

7.8CVSS

8.8AI Score

0.001EPSS

2022-01-28 08:15 PM
64
alpinelinux
alpinelinux

CVE-2024-39133

Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at...

6.9AI Score

0.0004EPSS

2024-06-27 08:15 PM
2
alpinelinux
alpinelinux

CVE-2019-1387

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code....

8.8CVSS

9.2AI Score

0.087EPSS

2019-12-18 09:15 PM
26
alpinelinux
alpinelinux

CVE-2024-37894

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service...

6.3CVSS

6.4AI Score

0.0004EPSS

2024-06-25 08:15 PM
1
alpinelinux
alpinelinux

CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with git clone --no-local to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but...

8.1CVSS

7.7AI Score

0.0004EPSS

2024-05-14 08:15 PM
8
alpinelinux
alpinelinux

CVE-2024-32004

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1,...

8.1CVSS

7.9AI Score

0.0004EPSS

2024-05-14 07:15 PM
7
alpinelinux
alpinelinux

CVE-2024-32002

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a .git/ directory......

9CVSS

7.1AI Score

0.002EPSS

2024-05-14 07:15 PM
44
alpinelinux
alpinelinux

CVE-2023-29007

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted .gitmodules file with submodule URLs that are longer than 1024 characters can used to exploit a bug in...

7.8CVSS

8.2AI Score

0.004EPSS

2023-04-25 09:15 PM
43
alpinelinux
alpinelinux

CVE-2024-0553

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange,.....

7.5CVSS

6.1AI Score

0.008EPSS

2024-01-16 12:15 PM
25
alpinelinux
alpinelinux

CVE-2023-7101

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of.....

7.8CVSS

8.1AI Score

0.053EPSS

2023-12-24 10:15 PM
18
alpinelinux
alpinelinux

CVE-2024-5261

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to...

7.4AI Score

0.0004EPSS

2024-06-25 01:15 PM
3
alpinelinux
alpinelinux

CVE-2021-35559

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated...

5.3CVSS

5.4AI Score

0.002EPSS

2021-10-20 11:16 AM
21
alpinelinux
alpinelinux

CVE-2023-52426

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile...

5.5CVSS

5.9AI Score

0.001EPSS

2024-02-04 08:15 PM
9
alpinelinux
alpinelinux

CVE-2024-37371

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length...

7.3AI Score

0.0004EPSS

2024-06-28 11:15 PM
1
alpinelinux
alpinelinux

CVE-2024-37370

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the...

7.2AI Score

0.0004EPSS

2024-06-28 10:15 PM
alpinelinux
alpinelinux

CVE-2024-29040

This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure TPMS_ATTEST. For the field TPM2_GENERATED magic of this structure any number can.....

4.3CVSS

6.8AI Score

0.0004EPSS

2024-06-28 09:15 PM
9
alpinelinux
alpinelinux

CVE-2023-42464

A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in.....

9.8CVSS

6.9AI Score

0.041EPSS

2023-09-20 03:15 PM
21
alpinelinux
alpinelinux

CVE-2022-21443

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit.....

3.7CVSS

4.9AI Score

0.001EPSS

2022-04-19 09:15 PM
22
alpinelinux
alpinelinux

CVE-2023-6516

To keep its cache database efficient, named running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued....

7.5CVSS

7.2AI Score

0.001EPSS

2024-02-13 02:15 PM
6
alpinelinux
alpinelinux

CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still...

7.8CVSS

8AI Score

0.936EPSS

2020-11-19 07:15 PM
33
alpinelinux
alpinelinux

CVE-2022-3038

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

8.8CVSS

9.2AI Score

0.287EPSS

2022-09-26 04:15 PM
21
alpinelinux
alpinelinux

CVE-2023-52722

An issue was discovered in Artifex Ghostscript through 10.01.0. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1...

6.9AI Score

0.0004EPSS

2024-04-28 12:15 AM
1
osv
osv

CVE-2024-5127

In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any role, including those intended for Paid and Enterprise plans only. This issue arises due to insufficient backend validation of roles....

5.4CVSS

6.7AI Score

0.0004EPSS

2024-06-06 06:15 PM
1
alpinelinux
alpinelinux

CVE-2023-2033

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...

8.8CVSS

9.1AI Score

0.026EPSS

2023-04-14 07:15 PM
616
cve
cve

CVE-2023-51514

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr Team CBX Bookmark & Favorite allows Stored XSS.This issue affects CBX Bookmark & Favorite: from n/a through...

6.5CVSS

5.4AI Score

0.0004EPSS

2024-02-01 12:15 PM
22
alpinelinux
alpinelinux

CVE-2024-0567

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of....

7.5CVSS

7AI Score

0.001EPSS

2024-01-16 02:15 PM
18
cve
cve

CVE-2024-35628

Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through...

4.3CVSS

5.1AI Score

0.0004EPSS

2024-06-11 03:16 PM
24
alpinelinux
alpinelinux

CVE-2024-4877

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be...

7.2AI Score

EPSS

2024-06-24 11:11 AM
1
cve
cve

CVE-2022-38055

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum: from n/a through...

5.4CVSS

6.8AI Score

0.0004EPSS

2024-06-21 04:15 PM
23
alpinelinux
alpinelinux

CVE-2023-25815

In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the gettext() function's implicit initialization...

3.3CVSS

5.8AI Score

0.0005EPSS

2023-04-25 08:15 PM
20
alpinelinux
alpinelinux

CVE-2024-5535

Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected application beahviour...

7.3AI Score

0.0004EPSS

2024-06-27 11:15 AM
12
alpinelinux
alpinelinux

CVE-2021-30533

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted...

6.5CVSS

6.8AI Score

0.017EPSS

2021-06-07 08:15 PM
31
alpinelinux
alpinelinux

CVE-2022-2294

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

8.8CVSS

9.1AI Score

0.013EPSS

2022-07-28 02:15 AM
37
alpinelinux
alpinelinux

CVE-2022-3075

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML...

9.6CVSS

9.2AI Score

0.01EPSS

2022-09-26 04:15 PM
24
alpinelinux
alpinelinux

CVE-2023-28746

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local...

6.5CVSS

6.7AI Score

0.0004EPSS

2024-03-14 05:15 PM
7
alpinelinux
alpinelinux

CVE-2023-4863

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:...

8.8CVSS

8.8AI Score

0.609EPSS

2023-09-12 03:15 PM
263
Total number of security vulnerabilities96188