Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

22,186 advisories

Loading
Use after free in Neon external buffers High
GHSA-8mj7-wxmc-f424 was published for neon (Rust) Jun 17, 2022
Aliased mutable references from `tls_rand` & `TlsWyRand` Moderate
GHSA-p6gj-gpc8-f8xw was published for nanorand (Rust) Jun 17, 2022
AtomicBucket<T> unconditionally implements Send/Sync Moderate
GHSA-3hxh-7jxm-59x4 was published for metrics-util (Rust) Jun 17, 2022
`mopa` is technically unsound High
GHSA-8mv5-7x95-7wcf was published for mopa (Rust) Jun 17, 2022
Deserialization functions pass uninitialized memory to user-provided Read High
GHSA-m325-rxjv-pwph was published for messagepack-rs (Rust) Jun 17, 2022
Use after free in lru crate High
GHSA-qqmc-hwqp-8g2w was published for lru (Rust) Jun 17, 2022
XML External Entity Reference in drools Critical
CVE-2021-41411 was published for org.drools:drools-core (Maven) Jun 17, 2022
wnicholson
Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags Moderate
CVE-2021-33295 was published for joplin (npm) Jun 17, 2022
Insufficiently Protected Credentials in PowerJob High
CVE-2020-28865 was published for com.github.kfcfans:powerjob (Maven) Jun 17, 2022
Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord` High
GHSA-wc36-xgcc-jwpr was published for libp2p-core (Rust) Jun 17, 2022
Parser creates invalid uninitialized value High
GHSA-f67m-9j94-qv9j was published for hyper (Rust) Jun 16, 2022
Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` ) High
GHSA-28p5-7rg4-8v99 was published for gfx-auxil (Rust) Jun 16, 2022
`Read` on uninitialized buffer may cause UB ( `read_entry()` ) High
GHSA-p56p-gq3f-whg8 was published for flumedb (Rust) Jun 16, 2022
Generated code can read and write out of bounds in safe code Critical
GHSA-3jch-9qgp-4844 was published for flatbuffers (Rust) Jun 16, 2022
enum_map macro can cause UB when `Enum` trait is incorrectly implemented High
GHSA-rxhx-9fj6-6h2m was published for enum-map (Rust) Jun 16, 2022
KamilaBorowska
QueryInterface should call AddRef before returning pointer Moderate
GHSA-9rg7-3j4f-cf4x was published for derive-com-impl (Rust) Jun 16, 2022
Unsoundness in `dashmap` references High
GHSA-mpg5-fvwp-42m2 was published for dashmap (Rust) Jun 16, 2022
saethlin
`Read` on uninitialized memory may cause UB (fn preamble_skipcount()) High
GHSA-r67p-m7g9-gxw6 was published for csv-sniffer (Rust) Jun 16, 2022
Non-aligned u32 read in Chacha20 encryption and decryption High
GHSA-pmcv-mgcf-rvxg was published for crypto2 (Rust) Jun 16, 2022
`SegQueue` creates zero value of any type Moderate
GHSA-8gj8-hv75-gp94 was published for crossbeam (Rust) Jun 16, 2022
`SegQueue` creates zero value of any type Moderate
GHSA-6888-wf7j-34jq was published for crossbeam-queue (Rust) Jun 16, 2022
Channel creates zero value of any type High
GHSA-9g55-pg62-m8hh was published for crossbeam-channel (Rust) Jun 16, 2022
columnar: `Read` on uninitialized buffer may cause UB (ColumnarReadExt::read_typed_vec()) High
GHSA-cxcc-q839-2cw9 was published for columnar (Rust) Jun 16, 2022
Potential segfault in `localtime_r` invocations Moderate
GHSA-cqpr-pcm7-m3jc was published for chrono (Rust) Jun 16, 2022 withdrawn
KamilaBorowska penberg
InputStream::read_exact : `Read` on uninitialized buffer causes UB High
GHSA-hmx9-jm3v-33hv was published for buffoon (Rust) Jun 16, 2022
ProTip! Advisories are also available from the GraphQL API