GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
668
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
151 advisories
Filter by severity
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c.
High
Unreviewed
CVE-2017-12662
was published
May 13, 2022
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/map.c.
High
Unreviewed
CVE-2017-12663
was published
May 13, 2022
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteCALSImage in coders/cals.c.
High
Unreviewed
CVE-2017-12669
was published
May 13, 2022
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.
High
Unreviewed
CVE-2017-12668
was published
May 13, 2022
Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote...
High
Unreviewed
CVE-2017-5507
was published
May 13, 2022
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will...
High
Unreviewed
CVE-2019-3883
was published
May 13, 2022
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL...
High
Unreviewed
CVE-2019-3821
was published
May 13, 2022
A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16...
High
Unreviewed
CVE-2018-0471
was published
May 13, 2022
There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base...
High
Unreviewed
CVE-2017-13748
was published
May 13, 2022
Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a...
High
Unreviewed
CVE-2017-8309
was published
May 13, 2022
Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause...
High
Unreviewed
CVE-2016-0877
was published
May 13, 2022
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x...
High
Unreviewed
CVE-2009-2903
was published
May 2, 2022
Memory leak in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12...
High
Unreviewed
CVE-2008-3799
was published
May 2, 2022
The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and...
High
Unreviewed
CVE-2007-4103
was published
May 1, 2022
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which...
High
Unreviewed
CVE-2010-4657
was published
Apr 21, 2022
A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software...
High
Unreviewed
CVE-2022-20697
was published
Apr 16, 2022
A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with...
High
Unreviewed
CVE-2022-26353
was published
Mar 17, 2022
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of...
High
Unreviewed
CVE-2020-22844
was published
Mar 1, 2022
Uncontrolled Resource Consumption in promhttp
High
CVE-2022-21698
was published
for
github.com/prometheus/client_golang
(Go)
Feb 16, 2022
A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding...
High
Unreviewed
CVE-2022-22170
was published
Jan 20, 2022
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet...
High
Unreviewed
CVE-2021-4190
was published
Dec 31, 2021
There is a memory leak vulnerability in CloudEngine 12800 V200R019C00SPC800, CloudEngine 5800...
High
Unreviewed
CVE-2021-40008
was published
Dec 14, 2021
Missing Release of Resource after Effective Lifetime in Apache Tomcat
High
CVE-2021-42340
was published
for
org.apache.tomcat:tomcat
(Maven)
Oct 15, 2021
S3 storage write is not aborted on errors leading to unbounded memory usage
High
GHSA-m6m5-pp4g-fcc8
was published
for
github.com/foxcpp/maddy
(Go)
Oct 6, 2021
ProTip!
Advisories are also available from the
GraphQL API