GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,262
Erlang
31
GitHub Actions
21
Go
2,030
Maven
5,000+
npm
3,732
NuGet
662
pip
3,409
Pub
12
RubyGems
891
Rust
865
Swift
36
Unreviewed advisories
All unreviewed
5,000+
205 advisories
Filter by severity
The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos...
High
Unreviewed
CVE-2006-6143
was published
May 1, 2022
The LDAP server (ns-slapd) in Sun Java System Directory Server 5.2 Patch4 and earlier and ONE...
High
Unreviewed
CVE-2006-4175
was published
May 1, 2022
ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when...
Moderate
Unreviewed
CVE-2003-1201
was published
Apr 29, 2022
An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS...
High
Unreviewed
CVE-2022-22198
was published
Apr 15, 2022
The affected product is vulnerable due to an invalid pointer initialization, which may lead to...
Moderate
Unreviewed
CVE-2022-21168
was published
Apr 13, 2022
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input...
Moderate
Unreviewed
CVE-2022-1122
was published
Mar 30, 2022
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior...
Moderate
Unreviewed
CVE-2021-3608
was published
Feb 25, 2022
Invalid drop of partially-initialized instances in the pooling instance allocator for modules with defined `externref` globals
Moderate
CVE-2022-23636
was published
for
wasmtime
(Rust)
Feb 16, 2022
Access of uninitialized pointer in the Intel(R) Trace Analyzer and Collector before version 2021...
Moderate
Unreviewed
CVE-2022-21156
was published
Feb 11, 2022
NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
Critical
GHSA-h6gw-r52c-724r
was published
for
tensorflow
(pip)
Feb 9, 2022
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an...
High
Unreviewed
CVE-2021-38409
was published
Dec 21, 2021
Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer...
Low
Unreviewed
CVE-2021-43746
was published
Dec 21, 2021
Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer...
Low
Unreviewed
CVE-2021-43030
was published
Dec 21, 2021
Incomplete validation in boosted trees code
Critical
CVE-2021-41208
was published
for
tensorflow
(pip)
Nov 10, 2021
Unitialized access in `EinsumHelper::ParseEquation`
High
CVE-2021-41201
was published
for
tensorflow
(pip)
Nov 10, 2021
Segfault while copying constant resource tensor
Moderate
CVE-2021-41204
was published
for
tensorflow
(pip)
Nov 10, 2021
Reference binding to `nullptr` in `tf.ragged.cross`
High
CVE-2021-41214
was published
for
tensorflow
(pip)
Nov 10, 2021
Undefined behavior via `nullptr` reference binding in sparse matrix multiplication
High
CVE-2021-41219
was published
for
tensorflow
(pip)
Nov 10, 2021
Assumed memory layout of std::net::SocketAddr
Moderate
GHSA-p5w9-856p-8q4g
was published
for
socket2
(Rust)
Aug 25, 2021
•
withdrawn
Access of Uninitialized Pointer in linked-hash-map
Critical
CVE-2020-25573
was published
for
linked-hash-map
(Rust)
Aug 25, 2021
Reference binding to nullptr in `RaggedTensorToSparse`
Moderate
CVE-2021-37656
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in `MatrixDiagV*` ops
Moderate
CVE-2021-37657
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in `MatrixSetDiagV*` ops
Moderate
CVE-2021-37658
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in boosted trees
Moderate
CVE-2021-37662
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in `RaggedTensorToVariant`
High
CVE-2021-37666
was published
for
tensorflow
(pip)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API