24h | 7d | 30d

Overview

  • curl
  • curl

05 Feb 2025
Published
12 Jun 2025
Updated

CVSS
Pending
EPSS
0.45%

KEV

Description

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • OpenSSL
  • OpenSSL

30 Sep 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.04%

KEV

Description

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • OpenSSL
  • OpenSSL

30 Sep 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.04%

KEV

Description

Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • PostgreSQL
  • postgresql

16 Aug 2017
Published
16 Sep 2024
Updated

CVSS
Pending
EPSS
33.12%

KEV

Description

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2020-25694 CVE-2020-25613 CVE-2019-3881 CVE-2018-25032 CVE-2018-1115 CVE-2018-10915 CVE-2018-1058 CVE-2018-1053 CVE-2017-7546 CVE-2017-7484 CVE-2017-15098 CVE-2017-14798 CVE-2016-7954 CVE-2016-7048 CVE-2016-5424 CVE-2016-5423 CVE-2016-0766 CVE-2015-3167 CVE-2015-3166
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

06 Oct 2020
Published
04 Aug 2024
Updated

CVSS
Pending
EPSS
0.27%

KEV

Description

An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2020-25694 CVE-2020-25613 CVE-2019-3881 CVE-2018-25032 CVE-2018-1115 CVE-2018-10915 CVE-2018-1058 CVE-2018-1053 CVE-2017-7546 CVE-2017-7484 CVE-2017-15098 CVE-2017-14798 CVE-2016-7954 CVE-2016-7048 CVE-2016-5424 CVE-2016-5423 CVE-2016-0766 CVE-2015-3167 CVE-2015-3166
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • postgresql

16 Nov 2020
Published
04 Aug 2024
Updated

CVSS
Pending
EPSS
0.36%

KEV

Description

A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2020-25694 CVE-2020-25613 CVE-2019-3881 CVE-2018-25032 CVE-2018-1115 CVE-2018-10915 CVE-2018-1058 CVE-2018-1053 CVE-2017-7546 CVE-2017-7484 CVE-2017-15098 CVE-2017-14798 CVE-2016-7954 CVE-2016-7048 CVE-2016-5424 CVE-2016-5423 CVE-2016-0766 CVE-2015-3167 CVE-2015-3166
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • PostgreSQL Global Development Group
  • postgresql

09 Aug 2018
Published
05 Aug 2024
Updated

CVSS v3.0
HIGH (8.5)
EPSS
1.75%

KEV

Description

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2020-25694 CVE-2020-25613 CVE-2019-3881 CVE-2018-25032 CVE-2018-1115 CVE-2018-10915 CVE-2018-1058 CVE-2018-1053 CVE-2017-7546 CVE-2017-7484 CVE-2017-15098 CVE-2017-14798 CVE-2016-7954 CVE-2016-7048 CVE-2016-5424 CVE-2016-5423 CVE-2016-0766 CVE-2015-3167 CVE-2015-3166
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

09 Dec 2016
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
3.40%

KEV

Description

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2020-25694 CVE-2020-25613 CVE-2019-3881 CVE-2018-25032 CVE-2018-1115 CVE-2018-10915 CVE-2018-1058 CVE-2018-1053 CVE-2017-7546 CVE-2017-7484 CVE-2017-15098 CVE-2017-14798 CVE-2016-7954 CVE-2016-7048 CVE-2016-5424 CVE-2016-5423 CVE-2016-0766 CVE-2015-3167 CVE-2015-3166
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

09 Dec 2016
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
1.67%

KEV

Description

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2020-25694 CVE-2020-25613 CVE-2019-3881 CVE-2018-25032 CVE-2018-1115 CVE-2018-10915 CVE-2018-1058 CVE-2018-1053 CVE-2017-7546 CVE-2017-7484 CVE-2017-15098 CVE-2017-14798 CVE-2016-7954 CVE-2016-7048 CVE-2016-5424 CVE-2016-5423 CVE-2016-0766 CVE-2015-3167 CVE-2015-3166
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • PostgreSQL Global Development Group
  • PostgreSQL

20 Nov 2019
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
1.81%

KEV

Description

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2020-25694 CVE-2020-25613 CVE-2019-3881 CVE-2018-25032 CVE-2018-1115 CVE-2018-10915 CVE-2018-1058 CVE-2018-1053 CVE-2017-7546 CVE-2017-7484 CVE-2017-15098 CVE-2017-14798 CVE-2016-7954 CVE-2016-7048 CVE-2016-5424 CVE-2016-5423 CVE-2016-0766 CVE-2015-3167 CVE-2015-3166
  • 0
  • 0
  • 0
  • 4h ago
Showing 111 to 120 of 132 CVEs