CVEs (67)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Debian FedoraprojectMariadb+4 more13500f Firmware A250 FirmwareCloud Volumes Ontap Mediator+10 moreJun 17, 2026 Mar 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic cu...Show more |
6Debian FedoraprojectLibexpat Project+3 more6Communications Metasolv Solution Debian LinuxFedora+3 moreJun 17, 2026 Jan 26, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. |
6Debian Libexpat ProjectNetapp+3 more7Clustered Data Ontap Communications Metasolv SolutionDebian Linux+4 moreJun 17, 2026 Jan 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Libexpat Project NetappSiemens+1 more8Active Iq Unified Manager Clustered Data OntapHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 6, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. |
5Debian Libexpat ProjectNetapp+2 more8Active Iq Unified Manager Debian LinuxHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 1, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). |
Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. Tenable ha...Show more |
Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator...Show more |
Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator priv...Show more |
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Ness...Show more |
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Ness...Show more |
10Fedoraproject FreebsdMcafee+7 more33Capture Client Cloud Volumes Ontap MediatorCommerce Guided Search+30 moreJun 17, 2026 Mar 25, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in t...Show more |
12Checkpoint DebianFedoraproject+9 more106Active Iq Unified Manager Capture ClientCloud Volumes Ontap Mediator+103 moreJun 17, 2026 Mar 25, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the...Show more |
A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a...Show more |
Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access to login into an exi...Show more |