GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,208 advisories
Filter by severity
There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference...
Moderate
Unreviewed
CVE-2018-20536
was published
May 13, 2022
Google Chrome before 16.0.912.63 does not properly handle YUV video frames, which allows remote...
Moderate
Unreviewed
CVE-2011-3910
was published
May 13, 2022
The PDF parser in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of...
Moderate
Unreviewed
CVE-2011-3906
was published
May 13, 2022
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial...
Moderate
Unreviewed
CVE-2011-3905
was published
May 13, 2022
Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers,...
Moderate
Unreviewed
CVE-2011-3893
was published
May 13, 2022
Google Chrome before 17.0.963.46 does not properly handle PDF FAX images, which allows remote...
Moderate
Unreviewed
CVE-2011-3963
was published
May 13, 2022
Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote...
Moderate
Unreviewed
CVE-2011-3908
was published
May 13, 2022
Google Chrome before 16.0.912.63 does not properly handle PDF documents, which allows remote...
Moderate
Unreviewed
CVE-2011-3911
was published
May 13, 2022
Google Chrome before 16.0.912.63 does not properly handle PDF cross references, which allows...
Moderate
Unreviewed
CVE-2011-3916
was published
May 13, 2022
Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote...
Moderate
Unreviewed
CVE-2011-2844
was published
May 13, 2022
Google Chrome before 14.0.835.163 does not properly handle Tibetan characters, which allows...
Moderate
Unreviewed
CVE-2011-2864
was published
May 13, 2022
Google Chrome before 14.0.835.163 does not properly handle Khmer characters, which allows remote...
Moderate
Unreviewed
CVE-2011-2850
was published
May 13, 2022
Google Chrome before 14.0.835.163 does not properly handle triangle arrays, which allows remote...
Moderate
Unreviewed
CVE-2011-2858
was published
May 13, 2022
Google Chrome before 14.0.835.163 does not properly handle video, which allows remote attackers...
Moderate
Unreviewed
CVE-2011-2851
was published
May 13, 2022
Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote...
Moderate
Unreviewed
CVE-2011-2843
was published
May 13, 2022
Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers...
Moderate
Unreviewed
CVE-2011-3234
was published
May 13, 2022
hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a...
Moderate
Unreviewed
CVE-2018-20124
was published
May 13, 2022
The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote...
Moderate
Unreviewed
CVE-2017-8845
was published
May 13, 2022
Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote...
Moderate
Unreviewed
CVE-2011-2794
was published
May 13, 2022
Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote...
Moderate
Unreviewed
CVE-2011-2803
was published
May 13, 2022
The NPAPI implementation in Google Chrome before 12.0.742.112 does not properly handle strings,...
Moderate
Unreviewed
CVE-2011-2345
was published
May 13, 2022
Google Chrome before 11.0.696.57 does not properly handle SVG documents, which allows remote...
Moderate
Unreviewed
CVE-2011-1445
was published
May 13, 2022
Google Chrome before 11.0.696.57 does not properly handle PDF documents with multipart encoding,...
Moderate
Unreviewed
CVE-2011-1455
was published
May 13, 2022
The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in...
Moderate
Unreviewed
CVE-2016-10198
was published
May 13, 2022
The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins...
Moderate
Unreviewed
CVE-2017-5846
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API