CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attac...Show more |
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Nov 12, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash). |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character). |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the con...Show more |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the bas...Show more |
2Debian Nlnetlabs2Debian Linux RoutinatorJun 17, 2026 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in thes...Show more |
2Debian Nlnetlabs2Debian Linux RoutinatorJun 17, 2026 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively s...Show more |
2Debian Fort Validator Project2Debian Linux Fort ValidatorJun 17, 2026 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Or...Show more |
3Debian FedoraprojectGolang3Debian Linux FedoraGoJun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation. |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Nov 5, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 vim is vulnerable to Use of Uninitialized Variable |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Nov 5, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
2Bluez Debian2Bluez Debian LinuxJun 17, 2026 Nov 4, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call. |
4Debian LinuxOracle+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Nov 4, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. |
3Debian LlhttpOracle3Debian Linux GraalvmLlhttpJun 17, 2026 Nov 3, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. |
2Debian Htmldoc Project2Debian Linux HtmldocJun 17, 2026 Nov 3, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Nov 3, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. |