CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectKicad3Debian Linux FedoraKicad EdaJun 17, 2026 Feb 4, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more |
3Debian FedoraprojectKicad3Debian Linux FedoraKicad EdaJun 17, 2026 Feb 4, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more |
3Debian FedoraprojectSymfony3Debian Linux FedoraTwigJun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions th...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Feb 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidenti...Show more |
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0. |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Feb 4, 2022 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit th...Show more |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Feb 4, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execut...Show more |
2Atftp Project Debian2Atftp Debian LinuxJun 17, 2026 Feb 4, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 4, 2022 N/A· v4 3.3 LOW· v3 1.9 LOW· v2 An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is...Show more |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 2, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use After Free in GitHub repository vim/vim prior to 8.2. |
4Debian FedoraprojectPostgresql+1 more4Debian Linux FedoraPostgresql Jdbc Driver+1 moreJun 17, 2026 Feb 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker con...Show more |
2Debian Minetest2Debian Linux MinetestJun 17, 2026 Feb 2, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In Minetest before 5.4.0, players can add or subtract items from a different player's inventory. |
2Debian Minetest2Debian Linux MinetestJun 17, 2026 Feb 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 1, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. |
5Debian FedoraprojectJenkins+2 more11Commerce Guided Search Communications Brm Elastic Charging EngineCommunications Cloud Native Core Automated Test Suite+8 moreJun 17, 2026 Feb 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel exe...Show more |
2Debian Twistedmatrix2Debian Linux TreqJun 17, 2026 Feb 1, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such co...Show more |
3Debian FedoraprojectMariadb3Debian Linux FedoraMariadbJun 17, 2026 Feb 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used. |
4Canonical DebianFedoraproject+1 more5Debian Linux Extra Packages For Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 31, 2022 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authenticatio...Show more |