CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 20, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts()....Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115....Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-C...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently g...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Fire...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox E...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR <...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thun...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 20, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added i...Show more |
3Canonical DebianTianocore3Debian Linux Edk2LxdJun 17, 2026 Feb 14, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. |
6Debian FedoraprojectIsc+3 more8Active Iq Unified Manager BindBootstrap Os+5 moreJun 17, 2026 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in...Show more |
3Debian FedoraprojectOpenidc3Debian Linux FedoraMod Auth OpenidcJun 17, 2026 Feb 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validatio...Show more |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 11, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stac...Show more |
2Debian Rhonabwy Project2Debian Linux RhonabwyJun 17, 2026 Feb 11, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The...Show more |
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel. |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 5, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 5, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or...Show more |