CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Intel2Connection Manager Debian LinuxJun 17, 2026 Jun 9, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA). |
4Ckeditor DebianDrupal+1 more4Ckeditor Debian LinuxDrupal+1 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!>...Show more |
5Arm BroadcomDebian+2 more8Bcm2711 Core I7 10700kCore I7 7700k+5 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and co...Show more |
4Debian EclipseNetapp+1 more8Active Iq Unified Manager Communications Cloud Native Core PolicyDebian Linux+5 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This...Show more |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different...Show more |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. |
2Debian Vmware2Debian Linux RabbitmqJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending mali...Show more |
4Debian FedoraprojectGnupg+1 more8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for...Show more |
3Debian OracleWireshark5Debian Linux Enterprise Manager Ops CenterInstantis Enterprisetrack+2 moreJun 17, 2026 Jun 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file |
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), wh...Show more |
2Debian Inverse2Debian Linux SogoJun 17, 2026 Jun 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authent...Show more |
3Debian EntrouvertFedoraproject3Debian Linux FedoraLassoJun 17, 2026 Jun 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c. |
2Debian Freedesktop2Debian Linux Xdg UtilsNov 21, 2024 Jun 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file. |
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attac...Show more |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c. |
4Debian FedoraprojectQemu+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null. |