GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,298
Erlang
31
GitHub Actions
21
Go
2,063
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
876
Swift
36
Unreviewed advisories
All unreviewed
5,000+
103 advisories
Filter by severity
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc)...
High
Unreviewed
CVE-2017-11554
was published
May 13, 2022
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser...
High
Unreviewed
CVE-2017-11556
was published
May 13, 2022
There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval:...
High
Unreviewed
CVE-2017-12964
was published
May 13, 2022
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in...
High
Unreviewed
CVE-2017-5839
was published
May 13, 2022
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of...
High
Unreviewed
CVE-2017-9304
was published
May 13, 2022
In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the...
High
Unreviewed
CVE-2017-9729
was published
May 13, 2022
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause...
High
Unreviewed
CVE-2017-9766
was published
May 13, 2022
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name...
High
Unreviewed
CVE-2018-9918
was published
May 13, 2022
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery...
High
Unreviewed
CVE-2016-3627
was published
May 14, 2022
Improper path handling in Kustomization files allows for denial of service
High
CVE-2022-24878
was published
for
github.com/fluxcd/flux2
(Go)
May 20, 2022
An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match...
High
Unreviewed
CVE-2019-11413
was published
May 24, 2022
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions...
High
Unreviewed
CVE-2019-13124
was published
May 24, 2022
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions...
High
Unreviewed
CVE-2019-13123
was published
May 24, 2022
The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print()...
High
Unreviewed
CVE-2018-16300
was published
May 24, 2022
The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.
High
Unreviewed
CVE-2018-16452
was published
May 24, 2022
An exploitable denial-of-service vulnerability exists in the mdnscap binary of the CUJO Smart...
High
Unreviewed
CVE-2018-4002
was published
May 24, 2022
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean...
High
Unreviewed
CVE-2020-12243
was published
May 24, 2022
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via...
High
Unreviewed
CVE-2020-28196
was published
May 24, 2022
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack...
High
Unreviewed
CVE-2020-8285
was published
May 24, 2022
An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c...
High
Unreviewed
CVE-2021-28040
was published
May 24, 2022
The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a...
High
Unreviewed
CVE-2020-1898
was published
May 24, 2022
OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are...
High
Unreviewed
CVE-2021-27432
was published
May 24, 2022
A stack overflow in libyang <= v1.0.225 can cause a denial of service through function...
High
Unreviewed
CVE-2021-28903
was published
May 24, 2022
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and...
High
Unreviewed
CVE-2021-27434
was published
May 24, 2022
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed...
High
Unreviewed
CVE-2021-3530
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API