CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectLibarchive+1 more4Debian Linux FedoraLibarchive+1 moreJun 17, 2026 Nov 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the...Show more |
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the se...Show more |
2Debian Heimdal Project2Debian Linux HeimdalJun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) a...Show more |
4Apple DebianLibtiff+1 more7Active Iq Unified Manager Debian LinuxIpados+4 moreJun 17, 2026 Nov 13, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to in...Show more |
3Debian FedoraprojectNetatalk3Debian Linux FedoraNetatalkJun 17, 2026 Nov 12, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS). |
3Debian FedoraprojectXfce3Debian Linux FedoraXfce4 SettingsJun 17, 2026 Nov 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper. |
4Debian FedoraprojectVarnish Software+1 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in th...Show more |
Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch...Show more |
Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectSysstat Project3Debian Linux FedoraSysstatJun 17, 2026 Nov 8, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocat...Show more |
3Debian Net SnmpNetapp6Debian Linux H300s FirmwareH410s Firmware+3 moreJun 17, 2026 Nov 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet...Show more |
3Debian Net SnmpNetapp6Debian Linux H300s FirmwareH410s Firmware+3 moreJun 17, 2026 Nov 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a c...Show more |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 Nov 6, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate att...Show more |
2Debian Jhead Project2Debian Linux JheadJun 17, 2026 Nov 4, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u. |
3Debian FedoraprojectPixman3Debian Linux FedoraPixmanJun 17, 2026 Nov 3, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. |
2Debian Xmldom Project2Debian Linux XmldomJun 17, 2026 Nov 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root n...Show more |