CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests. |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3. |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandw...Show more |
3Debian QemuRedhat3Debian Linux Enterprise LinuxQemuJun 17, 2026 May 13, 2021 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to th...Show more |
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 May 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash. |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 May 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integr...Show more |
3Debian FedoraprojectLibrdf3Debian Linux FedoraRaptor Rdf Syntax LibraryJun 17, 2026 May 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 13, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat f...Show more |
3Debian FedoraprojectSchedmd3Debian Linux FedoraSlurmJun 17, 2026 May 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling. |
4Debian FedoraprojectLinux+1 more10Cloud Backup Debian LinuxFedora+7 moreJul 30, 2026 May 12, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with...Show more |
3Debian FedoraprojectSamba3Debian Linux FedoraSambaJun 17, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a...Show more |
3Debian FedoraprojectSamba3Debian Linux FedoraSambaJun 17, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest thr...Show more |
3Debian FedoraprojectRedhat4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 11, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which w...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 May 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality. |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 May 11, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and proc...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 May 11, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an...Show more |
4Arista DebianLinux+1 more8C 65 Firmware C 75 FirmwareDebian Linux+5 moreJun 17, 2026 May 11, 2021 N/A· v4 5.4 MEDIUM· v3 3.2 LOW· v2 An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and...Show more |
5Arista CiscoDebian+2 more1661100 4p Firmware 1100 8p Firmware1100 Firmware+163 moreJun 17, 2026 May 11, 2021 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected...Show more |