| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability. |
| Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fm6v-8625-99jf |
| nltk is vulnerable to Inefficient Regular Expression Complexity |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior to 3.3.8.249. |
| jsoneditor is vulnerable to Inefficient Regular Expression Complexity |
| inflect is vulnerable to Inefficient Regular Expression Complexity |
| firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure. |
| code-server is vulnerable to Inefficient Regular Expression Complexity |
| ansi-regex is vulnerable to Inefficient Regular Expression Complexity |
| object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| taro is vulnerable to Inefficient Regular Expression Complexity |
| nth-check is vulnerable to Inefficient Regular Expression Complexity |
| vim is vulnerable to Use After Free |
| semver-regex is vulnerable to Inefficient Regular Expression Complexity |
| vim is vulnerable to Heap-based Buffer Overflow |
| nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity |
| vim is vulnerable to Heap-based Buffer Overflow |
| # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be exploited. **Fixed in**: [b3ba9978](https://github.com/ohmyzsh/ohmyzsh/commit/b3ba9978). **Impacted areas**: - `pygmalion` theme. - `pygmalion-virtualenv` theme. - `refined` theme. |
| validator.js is vulnerable to Inefficient Regular Expression Complexity |