CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Artifex DebianFedoraproject3Debian Linux FedoraGhostscriptJun 17, 2026 Jun 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). |
2Debian Shibboleth2Debian Linux XmltoolingJun 17, 2026 Jun 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.) |
5Debian FedoraprojectLinux+2 more9Debian Linux Enterprise LinuxFedora+6 moreJun 17, 2026 Jun 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been fre...Show more |
4Apple DebianFedoraproject+1 more4Cups Debian LinuxFedora+1 moreJun 17, 2026 Jun 22, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging serv...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can b...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 18, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 18, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c. |
4Canonical DebianLinux+1 more8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Jun 16, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 16, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal in...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Jun 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocke...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jun 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jun 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jun 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jun 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) |
3Debian FedoraprojectVmware3Debian Linux FedoraToolsJun 17, 2026 Jun 13, 2023 N/A· v4 3.9 LOW· v3 N/A· v2 A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. |
3Debian LinuxNetapp3Debian Linux Hci Baseboard Management ControllerLinux KernelJun 17, 2026 Jun 9, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel...Show more |
3Debian FedoraprojectFreedesktop3Dbus Debian LinuxFedoraJun 17, 2026 Jun 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic,...Show more |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Jun 7, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in t...Show more |