Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-xvr7-p2c6-j83w
  • SwiftURL/github.com/apple/swift-nio-http2
swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability 13 Aug
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-84m3-f99p-cqx5
  • PyPI/executorch
  • Maven/org.pytorch:executorch-android
  • SwiftURL/executorch
ExecuTorch integer overflow vulnerability 08 Aug
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-9m39-3mf3-xwch
  • PyPI/executorch
  • Maven/org.pytorch:executorch-android
  • SwiftURL/executorch
ExecuTorch heap buffer overflow vulnerability 08 Aug
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-f9hx-c6jf-3qxm
  • PyPI/executorch
  • Maven/org.pytorch:executorch-android
  • SwiftURL/executorch
ExecuTorch out-of-bounds access vulnerability 08 Aug
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-hj95-mhgf-jxc4
  • PyPI/executorch
  • Maven/org.pytorch:executorch-android
  • SwiftURL/executorch
ExecuTorch integer overflow vulnerability 08 Aug
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-xc7w-r669-48pf
  • PyPI/executorch
  • Maven/org.pytorch:executorch-android
  • SwiftURL/executorch
ExecuTorch vulnerable to Heap-based Buffer Overflow 08 Aug
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-h952-963h-rv99
  • PyPI/executorch
  • Maven/org.pytorch:executorch-android
  • SwiftURL/executorch
ExecuTorch vulnerable to Heap-based Buffer Overflow attack 11 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-wc9m-r3v6-9p5h
  • SwiftURL/github.com/sparkle-project/Sparkle
Sparkle Signing Checks Bypass 04 Feb
  • Fix available
  • Severity - 7.3 (High)
GHSA-w8xv-rwgf-4fwh
  • SwiftURL/github.com/apple/swift-asn1
CVE-2025-0343: Swift ASN.1 can crash when parsing maliciously formed BER/DER 14 Jan
  • Fix available
GHSA-fmq6-4w57-2w3v
  • SwiftURL/github.com/shareup/wasm-interpreter-apple
  • PyPI/pywasm3
  • crates.io/wasm3
wasm3 uncontrolled memory allocation vulnerability 09 Nov 2024
  • No fix available
  • Severity - 6.9 (Medium)
GHSA-x768-cvr2-345r
  • SwiftURL/github.com/swift-server/swift-prometheus
Un-sanitized metric name or labels can be used to take over exported metrics 29 Mar 2024
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-whx6-m9j4-w2m2
  • SwiftURL/github.com/ibireme/yyjson
yyjson has a Double Free vulnerability 29 Feb 2024
  • Fix available
  • Severity - 8.8 (High)
GHSA-r6r4-5pr8-gjcp
  • SwiftURL/github.com/vapor/vapor
Vapor contains an integer overflow in URI leading to potential host spoofing 03 Jan 2024
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-5844-q3fc-56rh
  • npm/pubnub
  • Maven/com.pubnub:pubnub-kotlin
  • Maven/com.pubnub:pubnub
  • Go/github.com/pubnub/go/v7
  • Go/github.com/pubnub/go
  • ... 9 more
pubnub Insufficient Entropy vulnerability 06 Dec 2023
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-qppj-fm5r-hxr3
  • SwiftURL/github.com/apple/swift-nio-http2
  • Go/golang.org/x/net
  • Maven/org.apache.tomcat:tomcat-coyote
  • Maven/org.apache.tomcat.embed:tomcat-embed-core
  • Maven/org.eclipse.jetty.http2:http2-common
  • ... 7 more
HTTP/2 Stream Cancellation Attack 10 Oct 2023
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-3mwq-h3g6-ffhm
  • SwiftURL/github.com/vapor/vapor
Vapor's incorrect request error handling triggers server crash 05 Oct 2023
  • Fix available
  • Severity - 5.3 (Medium)