GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
306 advisories
Filter by severity
NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers...
Moderate
Unreviewed
CVE-2018-6253
was published
May 13, 2022
An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause...
Moderate
Unreviewed
CVE-2018-7174
was published
May 13, 2022
Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0...
Moderate
Unreviewed
CVE-2022-3190
was published
Sep 14, 2022
kamadak-exif vulnerable to Infinite loop when parsing PNG files
Moderate
CVE-2021-21235
was published
for
kamadak-exif
(Rust)
Oct 6, 2022
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local...
Moderate
Unreviewed
CVE-2016-8909
was published
May 13, 2022
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local...
Moderate
Unreviewed
CVE-2016-8910
was published
May 13, 2022
An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial...
Moderate
Unreviewed
CVE-2021-44924
was published
Dec 22, 2021
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
Moderate
Unreviewed
CVE-2020-25625
was published
May 24, 2022
Infinite Loop in Apache James
Moderate
CVE-2021-40111
was published
for
org.apache.james:james-server
(Maven)
Jan 8, 2022
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer...
Moderate
Unreviewed
CVE-2020-28916
was published
May 24, 2022
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where...
Moderate
Unreviewed
CVE-2022-28886
was published
Sep 25, 2022
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of...
Moderate
Unreviewed
CVE-2019-17350
was published
May 24, 2022
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while...
Moderate
Unreviewed
CVE-2021-20257
was published
Mar 17, 2022
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite...
Moderate
Unreviewed
CVE-2016-1981
was published
May 13, 2022
When in an endless loop, a website specifying a custom cursor using CSS could make it look like...
Moderate
Unreviewed
CVE-2020-15654
was published
May 24, 2022
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in...
Moderate
Unreviewed
CVE-2021-3416
was published
May 24, 2022
On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed...
Moderate
Unreviewed
CVE-2019-6638
was published
May 24, 2022
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of...
Moderate
Unreviewed
CVE-2019-17349
was published
May 24, 2022
The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly...
Moderate
Unreviewed
CVE-2016-7908
was published
May 13, 2022
The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization,...
Moderate
Unreviewed
CVE-2011-4621
was published
May 13, 2022
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other...
Moderate
Unreviewed
CVE-2014-0148
was published
Sep 30, 2022
The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators...
Moderate
Unreviewed
CVE-2015-8558
was published
May 13, 2022
net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG...
Moderate
Unreviewed
CVE-2010-3880
was published
May 13, 2022
org.apache.tika:tika-parsers has an Infinite Loop vulnerability
Moderate
CVE-2018-1339
was published
for
org.apache.tika:tika-parsers
(Maven)
Oct 17, 2018
In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
Moderate
Unreviewed
CVE-2019-14372
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API