GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,748
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
10,598 advisories
Filter by severity
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user...
Low
Unreviewed
CVE-2000-0519
was published
Apr 30, 2022
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a...
Low
Unreviewed
CVE-2000-0518
was published
Apr 30, 2022
Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent...
Low
Unreviewed
CVE-2000-0502
was published
Apr 30, 2022
The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to...
Low
Unreviewed
CVE-2000-0503
was published
Apr 30, 2022
Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by...
Low
Unreviewed
CVE-2000-0501
was published
Apr 30, 2022
The Protected Store in Windows 2000 does not properly select the strongest encryption when...
Low
Unreviewed
CVE-2000-0487
was published
Apr 30, 2022
FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large...
Low
Unreviewed
CVE-2000-0489
was published
Apr 30, 2022
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation...
Low
Unreviewed
CVE-2000-0485
was published
Apr 30, 2022
The MSWordView application in IMP creates world-readable files in the /tmp directory, which...
Low
Unreviewed
CVE-2000-0458
was published
Apr 30, 2022
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another...
Low
Unreviewed
CVE-2000-0439
was published
Apr 30, 2022
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non...
Low
Unreviewed
CVE-2000-0445
was published
Apr 30, 2022
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL...
Low
Unreviewed
CVE-2000-0406
was published
Apr 30, 2022
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local...
Low
Unreviewed
CVE-2000-0409
was published
Apr 30, 2022
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System...
Low
Unreviewed
CVE-2000-0402
was published
Apr 30, 2022
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection,...
Low
Unreviewed
CVE-2000-0382
was published
Apr 30, 2022
The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows...
Low
Unreviewed
CVE-2000-0375
was published
Apr 30, 2022
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to...
Low
Unreviewed
CVE-2000-0366
was published
Apr 30, 2022
Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain...
Low
Unreviewed
CVE-2000-0368
was published
Apr 30, 2022
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if...
Low
Unreviewed
CVE-2000-0379
was published
Apr 30, 2022
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world...
Low
Unreviewed
CVE-2000-0361
was published
Apr 30, 2022
The on-line help system options in Cisco routers allows non-privileged users without "enabled"...
Low
Unreviewed
CVE-2000-0345
was published
Apr 30, 2022
The Allaire Spectra container editor preview tool does not properly enforce object security,...
Low
Unreviewed
CVE-2000-0334
was published
Apr 30, 2022
The Windows 2000 domain controller allows a malicious user to modify Active Directory information...
Low
Unreviewed
CVE-2000-0311
was published
Apr 30, 2022
The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a...
Low
Unreviewed
CVE-2000-0309
was published
Apr 30, 2022
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete...
Low
Unreviewed
CVE-2000-0293
was published
Apr 30, 2022
ProTip!
Advisories are also available from the
GraphQL API