CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 14, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
4Apple DebianFedoraproject+1 more5Debian Linux FedoraMac Os X+2 moreJun 17, 2026 Feb 14, 2022 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion. |
4Debian FedoraprojectPuma+1 more4Debian Linux FedoraPuma+1 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being close...Show more |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Feb 11, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` w...Show more |
2Debian Skolelinux2Debian Edu Config Debian LinuxJun 17, 2026 Feb 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privile...Show more |
4Debian FedoraprojectLibtiff+1 more4Debian Linux FedoraLibtiff+1 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compi...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that c...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c. |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Feb 11, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release. |
3Debian GolangNetapp6Beegfs Csi Driver Cloud Insights Telegraf AgentDebian Linux+3 moreJun 17, 2026 Feb 11, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. |
3Debian GolangNetapp6Beegfs Csi Driver Cloud Insights Telegraf AgentDebian Linux+3 moreJun 17, 2026 Feb 11, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 10, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2. |
2Debian Htmldoc Project2Debian Linux HtmldocJun 17, 2026 Feb 9, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault). |
5Apple DebianFedoraproject+2 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Feb 9, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file,...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 9, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file,...Show more |
3Debian FedoraprojectTwisted3Debian Linux FedoraTwistedJun 17, 2026 Feb 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.Redir...Show more |