CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges. |
5Debian FedoraprojectHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potent...Show more |
2Debian Mono Project2Debian Linux MonoJun 17, 2026 Feb 22, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter. |
2Debian Libreswan2Debian Linux LibreswanJun 17, 2026 Feb 21, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length. |
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags progra...Show more |
2Apache Debian2Commons Fileupload Debian LinuxJun 17, 2026 Feb 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, li...Show more |
5Debian FedoraprojectGnu+2 more7Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+4 moreJun 17, 2026 Feb 15, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbache...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Feb 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in...Show more |
2Debian Haproxy2Debian Linux HaproxyJun 17, 2026 Feb 14, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names,...Show more |
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2. |
A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via ex...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 30, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to g...Show more |
2Debian Lemonldap Ng2Apache\ Debian LinuxJun 17, 2026 Jan 27, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is use...Show more |
2Debian Lemonldap Ng2Apache\ Debian LinuxJun 17, 2026 Jan 27, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE:...Show more |
2Debian Openstack4Cinder Debian LinuxGlance+1 moreJun 17, 2026 Jan 26, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a spec...Show more |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Jan 26, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file |
2Debian Libtiff2Debian Linux LibtiffJun 17, 2026 Jan 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image. |
2Debian Html Stripscripts Project2Debian Linux Html StripscriptsJun 17, 2026 Jan 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes. |
2Debian Trustwave2Debian Linux ModsecurityJun 17, 2026 Jan 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_...Show more |