GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,035
Maven
5,000+
npm
3,732
NuGet
662
pip
3,413
Pub
12
RubyGems
891
Rust
865
Swift
36
Unreviewed advisories
All unreviewed
5,000+
563 advisories
Filter by severity
The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause...
High
Unreviewed
CVE-2016-5042
was published
May 13, 2022
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
High
CVE-2017-16932
was published
for
nokogiri
(RubyGems)
May 13, 2022
An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8...
High
Unreviewed
CVE-2017-2909
was published
May 13, 2022
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to...
Moderate
Unreviewed
CVE-2013-7488
was published
May 5, 2022
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite...
Moderate
Unreviewed
CVE-2012-0248
was published
May 4, 2022
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2010-1282
was published
May 2, 2022
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows...
Moderate
Unreviewed
CVE-2009-2906
was published
May 2, 2022
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service ...
High
Unreviewed
CVE-2009-1270
was published
May 2, 2022
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird...
Moderate
Unreviewed
CVE-2006-6499
was published
May 1, 2022
aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of...
Moderate
Unreviewed
CVE-2005-2224
was published
May 1, 2022
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers...
Moderate
Unreviewed
CVE-2005-0851
was published
May 1, 2022
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the...
Moderate
Unreviewed
CVE-2018-5786
was published
Apr 30, 2022
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU...
Moderate
Unreviewed
CVE-2004-0748
was published
Apr 29, 2022
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote...
Moderate
Unreviewed
CVE-2004-0753
was published
Apr 29, 2022
Manipulated inline images can cause Infinite Loop in PyPDF2
Moderate
CVE-2022-24859
was published
for
PyPDF2
(pip)
Apr 22, 2022
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial...
Moderate
Unreviewed
CVE-2010-0207
was published
Apr 21, 2022
A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ...
High
Unreviewed
CVE-2022-21159
was published
Apr 16, 2022
Infinite loop in .Net Bond
High
CVE-2020-1469
was published
for
Bond.Core.CSharp
(NuGet)
Apr 8, 2022
Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.
Moderate
Unreviewed
CVE-2022-1222
was published
Apr 5, 2022
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer...
Moderate
Unreviewed
CVE-2022-24191
was published
Apr 5, 2022
An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
High
Unreviewed
CVE-2022-23352
was published
Mar 22, 2022
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while...
Moderate
Unreviewed
CVE-2021-20257
was published
Mar 17, 2022
openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates
High
CVE-2022-0778
was published
for
openssl-src
(Rust)
Mar 16, 2022
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header....
High
Unreviewed
CVE-2022-0711
was published
Mar 3, 2022
Denial of Service in docker2aci
Moderate
CVE-2016-8579
was published
for
github.com/appc/docker2aci
(Go)
Feb 15, 2022
ProTip!
Advisories are also available from the
GraphQL API