CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OwaspTrustwave3Debian Linux ModsecurityModsecurityJun 17, 2026 Jan 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent c...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries...Show more |
2Debian Openstack2Debian Linux SwiftJun 17, 2026 Jan 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that...Show more |
3Debian FedoraprojectRuby Git Project3Debian Linux FedoraRuby GitJun 17, 2026 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
2Debian Ruby Git Project2Debian Linux Ruby GitJun 17, 2026 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
3Debian FedoraprojectTorproject3Debian Linux FedoraTorJun 17, 2026 Jan 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002. |
3Debian LinuxNetapp3Debian Linux Hci Baseboard Management ControllerLinux KernelJun 17, 2026 Jan 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition. |
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_AC...Show more |
2Debian Openvswitch2Debian Linux OpenvswitchJun 17, 2026 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. |
2Debian Openvswitch2Debian Linux OpenvswitchJun 17, 2026 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. |
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 du...Show more |
Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short> |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service. |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 7.3 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure. |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 7.3 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service. |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service. |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tamperin...Show more |