GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,259
NuGet
760
pip
4,052
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,195 advisories
Filter by severity
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack...
Low
Unreviewed
CVE-2005-1880
was published
May 1, 2022
The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is...
Low
Unreviewed
CVE-2005-0824
was published
May 1, 2022
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite...
Low
Unreviewed
CVE-2005-0587
was published
May 1, 2022
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and...
Moderate
Unreviewed
CVE-2005-0004
was published
May 1, 2022
cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a...
High
Unreviewed
CVE-2002-2382
was published
Apr 30, 2022
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors...
High
Unreviewed
CVE-2002-2374
was published
Apr 30, 2022
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and...
Moderate
Unreviewed
CVE-2002-2323
was published
Apr 30, 2022
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow...
Moderate
Unreviewed
CVE-2002-0793
was published
Apr 30, 2022
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage...
Moderate
Unreviewed
CVE-2002-0725
was published
Apr 30, 2022
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user...
Low
Unreviewed
CVE-2001-1593
was published
Apr 30, 2022
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary...
Low
Unreviewed
CVE-2001-1494
was published
Apr 30, 2022
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends...
Moderate
Unreviewed
CVE-2001-1386
was published
Apr 30, 2022
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via...
Low
Unreviewed
CVE-2001-1378
was published
Apr 30, 2022
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by...
Moderate
Unreviewed
CVE-2001-1043
was published
Apr 30, 2022
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by...
Moderate
Unreviewed
CVE-2001-1042
was published
Apr 30, 2022
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite...
Low
Unreviewed
CVE-2001-0131
was published
Apr 30, 2022
Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an...
Low
Unreviewed
CVE-2000-1178
was published
Apr 30, 2022
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a...
Low
Unreviewed
CVE-2000-0972
was published
Apr 30, 2022
DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite...
Low
Unreviewed
CVE-2000-0715
was published
Apr 30, 2022
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as ...
Moderate
Unreviewed
CVE-2000-0342
was published
Apr 30, 2022
Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service ...
High
Unreviewed
CVE-1999-1593
was published
Apr 30, 2022
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows...
Low
Unreviewed
CVE-1999-1386
was published
Apr 30, 2022
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client...
Moderate
Unreviewed
CVE-1999-0981
was published
Apr 30, 2022
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
Moderate
Unreviewed
CVE-1999-0794
was published
Apr 30, 2022
FreeBSD allows local users to conduct a denial of service by creating a hard link from a device...
Moderate
Unreviewed
CVE-1999-0783
was published
Apr 30, 2022
ProTip!
Advisories are also available from the
GraphQL API