CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 18, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. |
2Debian Lemonldap Ng2Debian Linux Lemonldap\Jun 17, 2026 Jul 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos...Show more |
2Debian Lemonldap Ng2Debian Linux Lemonldap\Jun 17, 2026 Jul 18, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl...Show more |
2Debian Squid Cache2Debian Linux SquidJun 17, 2026 Jul 17, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses. |
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Jul 15, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-re...Show more |
4Amd DebianFedoraproject+1 more126A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+123 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. |
6Debian FedoraprojectLlhttp+3 more6Debian Linux FedoraLlhttp+3 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). |
4Debian LlhttpNodejs+1 more4Debian Linux LlhttpNode.js+1 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). |
6Debian FedoraprojectLlhttp+3 more6Debian Linux FedoraLlhttp+3 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). |
4Debian FedoraprojectNodejs+1 more4Debian Linux FedoraNode.js+1 moreJun 17, 2026 Jul 14, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP addr...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Jul 12, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could s...Show more |
5Debian FedoraprojectIntel+2 more129Core I3 6100 Firmware Core I3 6100e FirmwareCore I3 6100h Firmware+126 moreJun 17, 2026 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 1.9 LOW· v2 Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack r...Show more |
4Amd DebianFedoraproject+1 more126A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+123 moreJun 17, 2026 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. |
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu...Show more |
20xacab Debian2Debian Linux Mat2Jun 17, 2026 Jul 8, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive informati...Show more |
4Debian EclipseJenkins+1 more8Debian Linux Element Plug In For Vcenter ServerHci Compute Node+5 moreJun 17, 2026 Jul 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can...Show more |
3Debian EclipseNetapp7Debian Linux Element Plug In For Vcenter ServerHci Compute Node+4 moreJun 17, 2026 Jul 7, 2022 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid inpu...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation...Show more |