GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,749
Maven
4,978
npm
3,509
NuGet
609
pip
3,084
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
197 advisories
Filter by severity
** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29,...
High
Unreviewed
CVE-2019-9192
was published
May 13, 2022
An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in...
High
Unreviewed
CVE-2019-9144
was published
May 13, 2022
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image:...
High
Unreviewed
CVE-2019-9143
was published
May 13, 2022
An issue was discovered in the function mark_beginning_as_normal in nfa.c in flex 2.6.4. There is...
Moderate
Unreviewed
CVE-2019-6293
was published
May 13, 2022
An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack...
Moderate
Unreviewed
CVE-2019-6292
was published
May 13, 2022
An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14...
Moderate
Unreviewed
CVE-2019-6291
was published
May 13, 2022
An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02....
Moderate
Unreviewed
CVE-2019-6290
was published
May 13, 2022
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows...
Moderate
Unreviewed
CVE-2019-6285
was published
May 13, 2022
svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in...
Moderate
Unreviewed
CVE-2019-6131
was published
May 13, 2022
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a...
Moderate
Unreviewed
CVE-2019-11026
was published
May 13, 2022
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
Moderate
Unreviewed
CVE-2019-11024
was published
May 13, 2022
Apache ORC vulnerable to Uncontrolled Recursion
High
CVE-2018-8015
was published
for
org.apache.orc:orc
(Maven)
May 13, 2022
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31....
Moderate
Unreviewed
CVE-2018-18484
was published
May 13, 2022
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild...
Moderate
Unreviewed
CVE-2018-18020
was published
May 13, 2022
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a stack exhaustion vulnerability. An...
Moderate
Unreviewed
CVE-2018-1158
was published
May 13, 2022
EOSIO/eos eos version after commit f1545dd0ae2b77580c2236fdb70ae7138d2c7168 contains a stack...
Critical
Unreviewed
CVE-2018-1000618
was published
May 13, 2022
Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS
Moderate
CVE-2019-1003011
was published
for
org.jenkins-ci.plugins:token-macro
(Maven)
May 13, 2022
Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an...
High
Unreviewed
CVE-2019-0001
was published
May 13, 2022
In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion...
High
Unreviewed
CVE-2017-11164
was published
May 13, 2022
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of...
High
Unreviewed
CVE-2017-9438
was published
May 13, 2022
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1...
High
Unreviewed
CVE-2018-6003
was published
May 13, 2022
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption...
Moderate
Unreviewed
CVE-2019-9904
was published
May 13, 2022
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could...
Moderate
Unreviewed
CVE-2018-0739
was published
May 13, 2022
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream:...
High
Unreviewed
CVE-2019-9543
was published
May 13, 2022
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream:...
High
Unreviewed
CVE-2019-9545
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API