CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2. |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set. |
6Apple DebianFedoraproject+3 more18Active Iq Unified Manager Debian LinuxFedora+15 moreJul 14, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applicati...Show more |
3Debian FedoraprojectPostgresql3Debian Linux FedoraPostgresql Jdbc DriverJun 17, 2026 Aug 3, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Aug 3, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of...Show more |
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution. |
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code. |
Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100. |
4Debian FedoraprojectGnu+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function. |
4Debian FedoraprojectLibtiff+1 more5Active Iq Unified Manager Debian LinuxFedora+2 moreJun 17, 2026 Jul 29, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" u...Show more |
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects. |
3Clusterlabs DebianFedoraproject3Booth Debian LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from...Show more |
3Debian LinuxNetapp7Active Iq Unified Manager Debian LinuxHci Compute Node+4 moreJun 17, 2026 Jul 27, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload at...Show more |
3Debian LinuxNetapp24A700s Firmware Active Iq Unified ManagerAff 500f Firmware+21 moreJun 17, 2026 Jul 27, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jul 26, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside...Show more |