GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,964 advisories
Filter by severity
2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to...
Moderate
Unreviewed
CVE-2007-6660
was published
May 1, 2022
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a...
Moderate
Unreviewed
CVE-2007-6607
was published
May 1, 2022
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via...
Moderate
Unreviewed
CVE-2007-6606
was published
May 1, 2022
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names...
Moderate
Unreviewed
CVE-2007-6536
was published
May 1, 2022
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a...
High
Unreviewed
CVE-2007-6524
was published
May 1, 2022
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient...
Moderate
Unreviewed
CVE-2007-6512
was published
May 1, 2022
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using...
Moderate
Unreviewed
CVE-2007-6514
was published
May 1, 2022
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which...
Moderate
Unreviewed
CVE-2007-6513
was published
May 1, 2022
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain...
Moderate
Unreviewed
CVE-2007-6502
was published
May 1, 2022
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request...
Moderate
Unreviewed
CVE-2007-6476
was published
May 1, 2022
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly...
High
Unreviewed
CVE-2007-6417
was published
May 1, 2022
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password...
Low
Unreviewed
CVE-2007-6418
was published
May 1, 2022
IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when ...
Moderate
Unreviewed
CVE-2007-6408
was published
May 1, 2022
Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to...
Moderate
Unreviewed
CVE-2007-6405
was published
May 1, 2022
Apache Tomcat Does Not Properly Handle Empty Requests
Moderate
CVE-2007-6286
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable...
Moderate
Unreviewed
CVE-2007-6283
was published
May 1, 2022
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for...
Low
Unreviewed
CVE-2007-6249
was published
May 1, 2022
TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct...
High
Unreviewed
CVE-2007-6221
was published
May 1, 2022
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and...
Low
Unreviewed
CVE-2007-6206
was published
May 1, 2022
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows...
Moderate
Unreviewed
CVE-2007-6197
was published
May 1, 2022
The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled,...
Low
Unreviewed
CVE-2007-6190
was published
May 1, 2022
The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP...
Moderate
Unreviewed
CVE-2007-6193
was published
May 1, 2022
index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information...
Moderate
Unreviewed
CVE-2007-6161
was published
May 1, 2022
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through...
Low
Unreviewed
CVE-2007-6150
was published
May 1, 2022
The SIP component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0, when Remote NAT...
Moderate
Unreviewed
CVE-2007-6095
was published
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API