CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache DebianFedoraproject+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Aug 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. |
4Ckeditor DebianFedoraproject+1 more12Application Express Banking Party ManagementCkeditor+9 moreJun 17, 2026 Aug 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability...Show more |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Aug 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Aug 10, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Aug 10, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code. |
2Debian Fig2dev Project2Debian Linux Fig2devJun 17, 2026 Aug 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format. |
2Debian Fig2dev Project2Debian Linux Fig2devJun 17, 2026 Aug 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format. |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Aug 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered...Show more |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Aug 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered...Show more |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Aug 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is...Show more |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Aug 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An...Show more |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Aug 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image f...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Aug 8, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer). |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Aug 8, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations. |
3Debian LinuxNetapp6Debian Linux Element SoftwareHci Bootstrap Os+3 moreJun 17, 2026 Aug 8, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those server...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Aug 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault. |
5Debian FedoraprojectGolang+2 more5Debian Linux FedoraGo+2 moreJun 17, 2026 Aug 8, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort. |
3Debian DigintFedoraproject3Btrbk Debian LinuxFedoraJun 17, 2026 Aug 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Aug 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_S...Show more |
3Debian FedoraprojectLynx Project3Debian Linux FedoraLynxJun 17, 2026 Aug 7, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. |