Main entries ~3681 :
Date Id Summary Products Score Patch Annotated
2014-03-01 CVE-2014-1912 Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string. Mac_os_x, Python N/A
2014-04-07 CVE-2014-0160 Heartbleed - The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug. Symantec_messaging_gateway, Ubuntu_linux, Debian_linux, Fedora, Filezilla_server, V100_firmware, V60_firmware, Micollab, Mivoice, Openssl, Opensuse, Enterprise_linux_desktop, Enterprise_linux_server, Enterprise_linux_server_aus, Enterprise_linux_server_eus, Enterprise_linux_server_tus, Enterprise_linux_workstation, Gluster_storage, Storage, Virtualization, S9922l_firmware, Application_processing_engine_firmware, Cp_1543\-1_firmware, Elan\-8\.2, Simatic_s7\-1500_firmware, Simatic_s7\-1500t_firmware, Wincc_open_architecture, Splunk 7.5
2021-09-08 CVE-2021-40346 An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs. Haproxy, Haproxy_docker_image 7.5
2016-06-08 CVE-2016-5108 Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file. Debian_linux, Vlc_media_player 9.8
2017-06-01 CVE-2017-8386 git-shell did not correctly validate the given project path, allowing an argument injection which leads to arbitrary file reads and in some configurations command execution. Ubuntu_linux, Debian_linux, Fedora, Git\-Shell, Leap 8.8
2018-04-06 CVE-2018-1000156 GNU patch is processd by ed. This allows arbitrary command executions through a line beginning with ! Ubuntu_linux, Debian_linux, Patch, Enterprise_linux_desktop, Enterprise_linux_server, Enterprise_linux_server_aus, Enterprise_linux_server_eus, Enterprise_linux_server_tus, Enterprise_linux_workstation 7.8
2018-06-08 CVE-2018-4222 There is an out-of-bounds read when compiling WebAssembly source buffers in WebKit. If the buffer is a view, the offset is added to the buffer twice before this is copied. This could allow memory off the heap to be read out of the source buffer, either though parsing exceptions or data sections when they are copied Icloud, Iphone_os, Itunes, Safari, Tvos, Watchos, Ubuntu_linux 8.8
Remaining NVD entries (unprocessed / no code available): ~260362 :
Date Id Summary Products Score Patch
2023-02-10 CVE-2022-24410 Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces. Alienware_13_r2_firmware, Alienware_13_r3_firmware, Alienware_15_r2_firmware, Alienware_15_r3_firmware, Alienware_15_r4_firmware, Alienware_17_r3_firmware, Alienware_17_r4_firmware, Alienware_17_r5_firmware, Alienware_area_51m_r1_firmware, Alienware_area_51m_r2_firmware, Alienware_aurora_r11_firmware, Alienware_aurora_r7_firmware, Alienware_aurora_r8_firmware, Alienware_aurora_r9_firmware, Alienware_m15_r1_firmware, Alienware_m15_r2_firmware, Alienware_m15_r3_firmware, Alienware_m15_r4_firmware, Alienware_m15_r6_firmware, Alienware_m17_r1_firmware, Alienware_m17_r2_firmware, Alienware_m17_r3_firmware, Alienware_m17_r4_firmware, Chengming_3977_firmware, Chengming_3980_firmware, Chengming_3988_firmware, Chengming_3990_firmware, Chengming_3991_firmware, Embedded_box_pc_5000_firmware, G15_5511_firmware, G3_15_3590_firmware, G3_3500_firmware, G3_3579_firmware, G3_3779_firmware, G5_15_5500_firmware, G5_15_5590_firmware, G5_5000_firmware, G5_5090_firmware, G7_15_7500_firmware, G7_15_7590_firmware, G7_17_7700_firmware, G7_17_7790_firmware, Inspiron_14_5410_2\-In\-1_firmware, Inspiron_15_3511_firmware, Inspiron_3268_firmware, Inspiron_3277_firmware, Inspiron_3280_firmware, Inspiron_3470, Inspiron_3471_firmware, Inspiron_3477_firmware, Inspiron_3480_aio_firmware, Inspiron_3480_firmware, Inspiron_3481_firmware, Inspiron_3482_firmware, Inspiron_3490_firmware, Inspiron_3493_firmware, Inspiron_3501_firmware, Inspiron_3502_firmware, Inspiron_3580_firmware, Inspiron_3581_firmware, Inspiron_3582_firmware, Inspiron_3584_firmware, Inspiron_3590_firmware, Inspiron_3593_firmware, Inspiron_3668_firmware, Inspiron_3670_firmware, Inspiron_3671_firmware, Inspiron_3780_firmware, Inspiron_3781_firmware, Inspiron_3782_firmware, Inspiron_3790_firmware, Inspiron_3793_firmware, Inspiron_3880_firmware, Inspiron_3881_firmware, Inspiron_3891_firmware, Inspiron_5300_firmware, Inspiron_5301_firmware, Inspiron_5310_firmware, Inspiron_5390_firmware, Inspiron_5391_firmware, Inspiron_5400_2\-In\-1_firmware, Inspiron_5400_firmware, Inspiron_5401_aio_firmware, Inspiron_5401_firmware, Inspiron_5402_firmware, Inspiron_5406_2\-In\-1_firmware, Inspiron_5408_firmware, Inspiron_5409_firmware, Inspiron_5477_firmware, Inspiron_5480_2\-In\-1_firmware, Inspiron_5480_firmware, Inspiron_5490_aio_firmware, Inspiron_5490_firmware, Inspiron_5491_2\-In\-1_firmware, Inspiron_5491_aio_firmware, Inspiron_5493_firmware, Inspiron_5494_firmware, Inspiron_5501_firmware, Inspiron_5502_firmware, Inspiron_5508_firmware, Inspiron_5509_firmware, Inspiron_5570_firmware, Inspiron_5583_firmware, Inspiron_5584_firmware, Inspiron_5590_firmware, Inspiron_5591_2\-In\-1_firmware, Inspiron_5593_firmware, Inspiron_5594_firmware, Inspiron_5680_firmware, Inspiron_5770_firmware, Inspiron_7000_firmware, Inspiron_7300_2\-In\-1_firmware, Inspiron_7300_firmware, Inspiron_7306_2\-In\-1_firmware, Inspiron_7391_2\-In\-1_firmware, Inspiron_7400_firmware, Inspiron_7490_firmware, Inspiron_7500_2\-In\-1_black_firmware, Inspiron_7500_2\-In\-1_silver_firmware, Inspiron_7500_firmware, Inspiron_7501_firmware, Inspiron_7506_2\-In\-1_firmware, Inspiron_7510_firmware, Inspiron_7590, Inspiron_7591, Inspiron_7591_2\-In\-1, Inspiron_7610_firmware, Inspiron_7700_aio_firmware, Inspiron_7706_2\-In\-1_firmware, Inspiron_7777_firmware, Inspiron_7790_firmware, Inspiron_7791_2\-In\-1_firmware, Latitude_13_3380_firmware, Latitude_3120_firmware, Latitude_3180_firmware, Latitude_3189_firmware, Latitude_3190_2\-In\-1_firmware, Latitude_3190_firmware, Latitude_3300_firmware, Latitude_3301_firmware, Latitude_3310_2\-In\-1_firmware, Latitude_3310_firmware, Latitude_3320_firmware, Latitude_3379_firmware, Latitude_3390_2\-In\-1_firmware, Latitude_3400_firmware, Latitude_3410_firmware, Latitude_3420_firmware, Latitude_3470_firmware, Latitude_3480_firmware, Latitude_3490_firmware, Latitude_3500_firmware, Latitude_3510_firmware, Latitude_3520_firmware, Latitude_3570_firmware, Latitude_3580_firmware, Latitude_3590_firmware 4.2
2023-02-10 CVE-2022-34452 PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs. Powerpath_management_appliance 2.7
2023-02-10 CVE-2022-34454 Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters. Emc_powerscale_onefs 6.7
2023-02-10 CVE-2023-22832 The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations and disallows XML External Entity resolution in the ExtractCCDAAttributes Processor. Nifi 7.5
2023-02-10 CVE-2023-22369 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-25011. Reason: This candidate is a duplicate of CVE-2023-25011. Notes: All CVE users should reference CVE-2023-25011 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. N/A N/A
2023-02-10 CVE-2022-43501 KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future ones. Kasago_ipv4, Kasago_ipv4_light, Kasago_ipv6\/v4_dual, Kasago_mobile_ipv6 9.1
2023-02-10 CVE-2023-23286 Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field from the login form. Provide_server 6.1