GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,137 advisories
Filter by severity
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
Moderate
Unreviewed
CVE-2018-20570
was published
May 13, 2022
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers...
Moderate
Unreviewed
CVE-2017-9125
was published
May 13, 2022
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote...
Moderate
Unreviewed
CVE-2017-9128
was published
May 13, 2022
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers...
Moderate
Unreviewed
CVE-2017-9123
was published
May 13, 2022
This vulnerability allows remote attackers to disclose sensitive information on vulnerable...
Moderate
Unreviewed
CVE-2019-6732
was published
May 13, 2022
** DISPUTED ** The libevt_record_values_read_event() function in libevt_record_values.c in libevt...
Moderate
Unreviewed
CVE-2018-8754
was published
May 13, 2022
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before...
Moderate
Unreviewed
CVE-2017-18344
was published
May 13, 2022
The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of...
Moderate
Unreviewed
CVE-2018-5683
was published
May 13, 2022
soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote...
Moderate
Unreviewed
CVE-2018-10017
was published
May 13, 2022
The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers...
Moderate
Unreviewed
CVE-2018-14016
was published
May 13, 2022
The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote...
Moderate
Unreviewed
CVE-2018-14017
was published
May 13, 2022
In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow...
Moderate
Unreviewed
CVE-2018-20458
was published
May 13, 2022
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows...
Moderate
Unreviewed
CVE-2018-20459
was published
May 13, 2022
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers...
Moderate
Unreviewed
CVE-2018-20457
was published
May 13, 2022
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter...
Moderate
Unreviewed
CVE-2016-5107
was published
May 13, 2022
An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the...
Moderate
Unreviewed
CVE-2018-7729
was published
May 13, 2022
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp...
Moderate
Unreviewed
CVE-2018-7728
was published
May 13, 2022
An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is...
Moderate
Unreviewed
CVE-2018-7730
was published
May 13, 2022
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function...
Moderate
Unreviewed
CVE-2018-19661
was published
May 13, 2022
It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a...
Moderate
Unreviewed
CVE-2019-3832
was published
May 13, 2022
There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that...
Moderate
Unreviewed
CVE-2018-19758
was published
May 13, 2022
The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device...
Moderate
Unreviewed
CVE-2016-10029
was published
May 13, 2022
The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS...
Moderate
Unreviewed
CVE-2017-11434
was published
May 13, 2022
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local...
Moderate
Unreviewed
CVE-2017-11334
was published
May 13, 2022
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest...
Moderate
Unreviewed
CVE-2017-13672
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API