GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,262
NuGet
760
pip
4,053
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
168 advisories
Filter by severity
src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink...
Low
Unreviewed
CVE-2012-2093
was published
May 17, 2022
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2012-2103
was published
May 17, 2022
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator...
Low
Unreviewed
CVE-2012-3329
was published
May 17, 2022
welcome.py in xdiagnose before 2.5.2ubuntu0.1 allows local users to overwrite arbitrary files via...
Low
Unreviewed
CVE-2012-5355
was published
May 17, 2022
(1) debian/postrm and (2) debian/localepurge.config in localepurge before 0.7.3.2 use tempfile to...
Low
Unreviewed
CVE-2014-1638
was published
May 17, 2022
syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe...
Low
Unreviewed
CVE-2014-1639
was published
May 17, 2022
pyxdg Arbitrary File Overwrite via Race Condition
Low
CVE-2014-1624
was published
for
pyxdg
(pip)
May 17, 2022
axiom-test.sh in axiom 20100701-1.1 uses tempfile to create a safe temporary file but appends a...
Low
Unreviewed
CVE-2014-1640
was published
May 17, 2022
The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via...
Low
Unreviewed
CVE-2014-1875
was published
May 17, 2022
The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the...
Low
Unreviewed
CVE-2011-4060
was published
May 17, 2022
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the...
Low
Unreviewed
CVE-2011-1073
was published
May 14, 2022
Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2010-2027
was published
May 14, 2022
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users...
Low
Unreviewed
CVE-2014-2893
was published
May 14, 2022
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create...
Low
Unreviewed
CVE-2014-2524
was published
May 14, 2022
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary...
Low
Unreviewed
CVE-2015-7758
was published
May 14, 2022
GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows...
Low
Unreviewed
CVE-2015-4156
was published
May 14, 2022
syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to...
Low
Unreviewed
CVE-2014-4372
was published
May 14, 2022
MySQL before 5.1.46 allows local users to delete the data and index files of another user's...
Low
Unreviewed
CVE-2010-1626
was published
May 13, 2022
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to...
Low
Unreviewed
CVE-2010-3691
was published
May 13, 2022
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a...
Low
Unreviewed
CVE-2014-7206
was published
May 13, 2022
The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink...
Low
Unreviewed
CVE-2011-1072
was published
May 13, 2022
The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2011-1144
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to...
Low
Unreviewed
CVE-2011-1031
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to...
Low
Unreviewed
CVE-2011-0702
was published
May 13, 2022
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to...
Low
Unreviewed
CVE-2011-4028
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API