CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into ret...Show more |
4Debian NetappPhp+1 more4Clustered Data Ontap Debian LinuxPhp+1 moreJun 17, 2026 Nov 29, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 24, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started i...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 24, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started i...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 24, 2021 N/A· v4 8.8 HIGH· v3 6.9 MEDIUM· v2 PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-dema...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 24, 2021 N/A· v4 8.8 HIGH· v3 6.9 MEDIUM· v2 PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-dema...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 24, 2021 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit....Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 24, 2021 N/A· v4 8.8 HIGH· v3 6.9 MEDIUM· v2 PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-dema...Show more |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Nov 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectIsync Project3Debian Linux FedoraIsyncJun 17, 2026 Nov 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line...Show more |
4Debian FedoraprojectPgbouncer+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Nov 22, 2021 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encrypt...Show more |
3Debian FedoraprojectLibrecad3Debian Linux FedoraLibdxfrwJun 17, 2026 Nov 19, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can prov...Show more |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Nov 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file ca...Show more |