CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Google2Chrome Debian LinuxJun 17, 2026 Nov 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Nov 2, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 2, 2021 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Oct 27, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
6Debian FedoraprojectIsc+3 more15Bind Cloud BackupDebian Linux+12 moreJun 17, 2026 Oct 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development b...Show more |
7Debian DrupalFedoraproject+4 more28Agile Plm Application ExpressBanking Platform+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fi...Show more |
7Debian DrupalFedoraproject+4 more29Agile Plm Application ExpressBanking Platform+26 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixe...Show more |
5Debian FedoraprojectNetapp+2 more5Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+2 moreJun 17, 2026 Oct 25, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged u...Show more |
3Debian FedoraprojectNothings3Debian Linux FedoraStb Image.hJun 17, 2026 Oct 21, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of ser...Show more |
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then us...Show more |
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Oct 21, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password. |
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. |
4Debian FedoraprojectWebkitgtk+1 more4Debian Linux FedoraWebkitgtk+1 moreJun 17, 2026 Oct 20, 2021 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox,...Show more |
4Debian FedoraprojectNetapp+1 more14Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+11 moreJun 17, 2026 Oct 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition:...Show more |
4Debian FedoraprojectNetapp+1 more14Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+11 moreJun 17, 2026 Oct 20, 2021 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 an...Show more |
4Debian FedoraprojectNetapp+1 more14Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+11 moreJun 17, 2026 Oct 20, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Editi...Show more |
4Debian FedoraprojectNetapp+1 more14Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+11 moreJun 17, 2026 Oct 20, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3...Show more |