Tagged “osv”
CVEs tagged osv, newest first.
5752 CVEsRSS
CVE-2021-37654High· 7.3Heap OOB and CHECK fail in `ResourceGather`
Heap OOB and CHECK fail in `ResourceGather`
CVE-2021-37691Medium· 5.5FPE in LSH in TFLite
FPE in LSH in TFLite
CVE-2021-37644Medium· 5.5`std::abort` raised from `TensorListReserve`
`std::abort` raised from `TensorListReserve`
CVE-2021-37673Medium· 5.5`CHECK`-fail in `MapStage`
`CHECK`-fail in `MapStage`
CVE-2021-32798Critical· 10.0Special Element Injection in notebook
Special Element Injection in notebook
CVE-2021-32797High· 7.4JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
CVE-2021-38554Medium· 5.3vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser (CVE-2021-38554)
A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the p…
CVE-2021-37705Critical· 10.0Improper Authorization and Origin Validation Error in OneFuzz
Improper Authorization and Origin Validation Error in OneFuzz
CVE-2021-29063High· 7.5ReDOS in Mpmath
ReDOS in Mpmath
CVE-2021-32813Medium· 4.8Header dropping in traefik
Header dropping in traefik
CVE-2021-32811High· 7.5Remote Code Execution via Script (Python) objects under Python 3
Remote Code Execution via Script (Python) objects under Python 3
CVE-2021-32807Medium· 4.4Remote Code Execution via unsafe classes in otherwise permitted modules
Remote Code Execution via unsafe classes in otherwise permitted modules
CVE-2021-32806Medium· 6.5URL Redirection to Untrusted Site ('Open Redirect') in Products.isurlinportal
URL Redirection to Untrusted Site ('Open Redirect') in Products.isurlinportal
CVE-2020-7964Medium· 5.3Missing Authentication for Critical Function in Saleor
Missing Authentication for Critical Function in Saleor
CVE-2021-32574High· 7.5Hashicorp Consul Missing SSL Certificate Validation
Hashicorp Consul Missing SSL Certificate Validation
CVE-2021-38511High· 7.5Links in archive can create arbitrary directories
Links in archive can create arbitrary directories
CVE-2021-32760Medium· 5.5containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760)
A flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expe…
CVE-2021-3602Medium· 5.5Buildah processes using chroot isolation may leak environment values to intermediate processes
Buildah processes using chroot isolation may leak environment values to intermediate processes
CVE-2021-32715Low· 3.1Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
CVE-2021-32714Medium· 5.9Integer Overflow in Chunked Transfer-Encoding
Integer Overflow in Chunked Transfer-Encoding
CVE-2020-36407High· 8.8libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
CVE-2021-32721Medium· 4.7Open Redirect in github.com/AndrewBurian/powermux
Open Redirect in github.com/AndrewBurian/powermux
CVE-2020-26242Medium· 6.5Denial of service in geth
Denial of service in geth
CVE-2020-15111Medium· 4.2CRLF vulnerability in Fiber
CRLF vulnerability in Fiber
CVE-2020-26241Medium· 6.5Shallow copy bug in geth
Shallow copy bug in geth
GHSA-vfvf-6gx5-mqv6High· 7.5Incorrect Authorization in ORY Oathkeeper
Incorrect Authorization in ORY Oathkeeper
CVE-2020-27846Critical· 9.8XML Processing error in github.com/crewjam/saml
XML Processing error in github.com/crewjam/saml
CVE-2020-26279High· 7.7Path traversal in github.com/ipfs/go-ipfs
Path traversal in github.com/ipfs/go-ipfs
GHSA-qvp4-rpmr-xwrrHigh· 7.5Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
CVE-2020-4053Low· 3.7Plugin archive directory traversal in Helm
Plugin archive directory traversal in Helm