Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bootstrap vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2022-26049
This affects the package com.diffplug.gradle:goomph prior to 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an m...
Diffplug Goomph
NA
CVE-2009-1154
Cisco IOS XR 3.8.1 and previous versions allows remote malicious users to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
Cisco Ios Xr 3.5
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.5.2
Cisco Ios Xr 3.5.4
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.2
Cisco Ios Xr 3.6.2
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.4
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.7.3
Cisco Ios Xr 3.8.0
Cisco Ios Xr
Cisco Ios Xr 3.4.1
Cisco Ios Xr 3.4.3
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.7.1
Cisco Ios Xr 3.6.1
NA
CVE-2009-2055
Cisco IOS XR 3.4.0 up to and including 3.8.1 allows remote malicious users to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
Cisco Ios Xr 3.4
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.1
Cisco Ios Xr 3.7.3
Cisco Ios Xr 3.8.1
Cisco Ios Xr 3.8.0
Cisco Ios Xr 3.4.3
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.6.2
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.5.2
Cisco Ios Xr 3.5.4
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.6.1
Cisco Ios Xr 3.4.2
Cisco Ios Xr 3.5
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.7.1
NA
CVE-2010-3035
Cisco IOS XR 3.4.0 up to and including 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote malicious users to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in Augus...
Cisco Ios Xr 3.4.2
Cisco Ios Xr 3.4.3
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.8.4
Cisco Ios Xr 3.9.0
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.1
Cisco Ios Xr 3.6.1
Cisco Ios Xr 3.6.2
Cisco Ios Xr 3.8.1
Cisco Ios Xr 3.8.2
Cisco Ios Xr 3.8.3
Cisco Ios Xr 3.5.4
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.7.3
Cisco Ios Xr 3.8.0
Cisco Ios Xr 3.5.2
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.7.1
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.9.1
7.2
CVSSv3
CVE-2023-2454
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
Postgresql Postgresql
Redhat Enterprise Linux 8.0
Redhat Software Collections -
Redhat Enterprise Linux 9.0
Fedoraproject Fedora 38
6.1
CVSSv3
CVE-2020-11022
In jQuery versions greater than or equal to 1.2 and prior to 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuer...
Jquery Jquery
Drupal Drupal
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Oracle Weblogic Server 12.1.3.0.0
Oracle Jdeveloper 11.1.1.9.0
Oracle Retail Back Office 14.1
Oracle Retail Back Office 14.0
Oracle Peoplesoft Enterprise Peopletools 8.56
Oracle Weblogic Server 10.3.6.0.0
Oracle Communications Webrtc Session Controller 7.2
Oracle Weblogic Server 12.2.1.3.0
Oracle Agile Product Lifecycle Management For Process 6.2.0.0
Oracle Peoplesoft Enterprise Peopletools 8.57
Oracle Application Testing Suite 13.3.0.1
Oracle Retail Returns Management 14.0
Oracle Retail Returns Management 14.1
Oracle Jdeveloper 12.2.1.3.0
Oracle Policy Automation Connector For Siebel 10.4.6
Oracle Financial Services Market Risk Measurement And Management 8.0.6
13 Github repositories
7.5
CVSSv3
CVE-2016-6355
Memory leak in Cisco IOS XR 5.1.x up to and including 5.1.3, 5.2.x up to and including 5.2.5, and 5.3.x up to and including 5.3.2 on ASR 9001 devices allows remote malicious users to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug...
Cisco Ios Xr 5.1.3
Cisco Ios Xr 5.2.0
Cisco Ios Xr 5.3.2
Cisco Ios Xr 5.2.3
Cisco Ios Xr 5.2.1
Cisco Ios Xr 5.2.2
Cisco Ios Xr 5.2.5
Cisco Ios Xr 5.1.1
Cisco Ios Xr 5.1.2
Cisco Ios Xr 5.3.1
Cisco Ios Xr 5.2.4
Cisco Ios Xr 5.1.0
Cisco Ios Xr 5.3.0
Cisco Ios Xr 5.1.1.k9sec
NA
CVE-2009-2056
Cisco IOS XR 3.8.1 and previous versions allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
Cisco Ios Xr 3.6.1
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.6
Cisco Ios Xr 3.5
Cisco Ios Xr 3.2.2
Cisco Ios Xr 3.2.1
Cisco Ios Xr 3.2
Cisco Ios Xr 3.1
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.4
Cisco Ios Xr 3.2.4
Cisco Ios Xr 3.2.3
Cisco Ios Xr 3.1.0
Cisco Ios Xr 3.0.1
Cisco Ios Xr 3.8.0
Cisco Ios Xr 3.7
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.7.1
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.1
7.4
CVSSv3
CVE-2019-1846
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent malicious user to trigger a denial...
Cisco Ios Xr 5.3.3
7.5
CVSSv3
CVE-2015-2688
buf_pullup in Tor prior to 0.2.4.26 and 0.2.5.x prior to 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote malicious users to cause a denial of service (assertion failure and daemon exit) via crafted packets.
Torproject Tor
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »