GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,019 advisories
Filter by severity
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is...
High
Unreviewed
CVE-2017-8394
was published
May 17, 2022
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is...
High
Unreviewed
CVE-2017-8395
was published
May 17, 2022
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is...
High
Unreviewed
CVE-2017-8392
was published
May 17, 2022
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users...
High
Unreviewed
CVE-2017-7374
was published
May 17, 2022
LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame...
High
Unreviewed
CVE-2017-15019
was published
May 17, 2022
nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer...
High
Unreviewed
CVE-2015-2297
was published
May 17, 2022
SQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c because it fails to...
High
Unreviewed
CVE-2017-15286
was published
May 17, 2022
p_lx_elf.cpp in UPX 3.94 mishandles ELF headers, which allows remote attackers to cause a denial...
High
Unreviewed
CVE-2017-15056
was published
May 17, 2022
The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a...
High
Unreviewed
CVE-2015-8270
was published
May 17, 2022
BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference...
High
Unreviewed
CVE-2016-10189
was published
May 17, 2022
The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a...
High
Unreviewed
CVE-2016-7997
was published
May 17, 2022
The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL...
High
Unreviewed
CVE-2017-14225
was published
May 17, 2022
cmds/servicemanager/service_manager.c in Android before commit...
High
Unreviewed
CVE-2014-3164
was published
May 17, 2022
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver...
High
Unreviewed
CVE-2017-15921
was published
May 17, 2022
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver...
High
Unreviewed
CVE-2017-15920
was published
May 17, 2022
tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a dbus triggered NULL pointer dereference in...
High
Unreviewed
CVE-2017-1000200
was published
May 17, 2022
A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products,...
High
Unreviewed
CVE-2017-13135
was published
May 17, 2022
The ff_vc1_mc_4mv_chroma4 function in libavcodec/vc1_mc.c in Libav 12.2 allows remote attackers...
High
Unreviewed
CVE-2017-17129
was published
May 17, 2022
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer...
High
Unreviewed
CVE-2017-17050
was published
May 17, 2022
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer...
High
Unreviewed
CVE-2017-16948
was published
May 17, 2022
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer...
High
Unreviewed
CVE-2017-17049
was published
May 17, 2022
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before...
High
Unreviewed
CVE-2017-8820
was published
May 17, 2022
In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a...
High
Unreviewed
CVE-2017-17439
was published
May 14, 2022
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL...
High
Unreviewed
CVE-2015-8917
was published
May 14, 2022
The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux...
High
Unreviewed
CVE-2016-3070
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API