CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Mar 21, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests wi...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Mar 21, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests wi...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Mar 21, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow m...Show more |
3Debian LinuxNetapp7Debian Linux H300sH410c+4 moreJun 17, 2026 Mar 16, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference). |
A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing t...Show more |
3Apache DebianUnbit3Debian Linux Http ServerUwsgiJun 17, 2026 Mar 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the...Show more |
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free. |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Mar 6, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file |
3Debian LinuxfoundationRedhat4Debian Linux Enterprise LinuxOpenshift Container Platform+1 moreJun 17, 2026 Mar 3, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount con...Show more |
2Debian Systemd Project2Debian Linux SystemdJun 17, 2026 Mar 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not...Show more |
Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc. |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cra...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cr...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cra...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craf...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. |
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Feb 25, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device. |