CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. Th...Show more |
2Debian Mozilla2Debian Linux ThunderbirdJun 17, 2026 Dec 19, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was...Show more |
2Debian Mozilla2Debian Linux ThunderbirdJun 17, 2026 Dec 19, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, an...Show more |
2Debian Openbsd2Debian Linux OpensshJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git...Show more |
2Debian Openbsd2Debian Linux OpensshJul 14, 2026 Dec 18, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only appli...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
2Debian Redhat4Ansible Automation Platform Ansible DeveloperAnsible Inside+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file...Show more |
4Debian RedhatTigervnc+1 more5Debian Linux Enterprise Linux EusTigervnc+2 moreJun 23, 2026 Dec 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information. |
4Debian RedhatTigervnc+1 more5Debian Linux Enterprise Linux EusTigervnc+2 moreJun 23, 2026 Dec 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possibl...Show more |
2Apple Debian7Debian Linux IpadosIphone Os+4 moreJun 17, 2026 Dec 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead...Show more |
3Debian FedoraprojectLibreoffice3Debian Linux FedoraLibreofficeJun 17, 2026 Dec 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar b...Show more |
3Debian FedoraprojectLibreoffice3Debian Linux FedoraLibreofficeJun 17, 2026 Dec 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video...Show more |
5Apple CanonicalDebian+2 more7Android Debian LinuxFedora+4 moreJun 17, 2026 Dec 8, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages w...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium secur...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 6, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interacti...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI inter...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
2Debian Sierrawireless2Aleos Debian LinuxJun 17, 2026 Dec 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairin...Show more |