CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Klibc Project2Debian Linux KlibcJun 17, 2026 Apr 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems. |
2Debian Klibc Project2Debian Linux KlibcJun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow. |
3Debian FedoraprojectGraphviz3Debian Linux FedoraGraphvizJun 17, 2026 Apr 29, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into...Show more |
2Debian Fluidsynth2Debian Linux FluidsynthJun 17, 2026 Apr 29, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file. |
2Debian Redhat4Ansible Automation Platform Ansible EngineAnsible Tower+1 moreJun 17, 2026 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attack...Show more |
4Debian IscNetapp+1 more14Active Iq Unified Manager Aff 500f FirmwareAff A250 Firmware+11 moreJun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 developm...Show more |
6Debian FedoraprojectIsc+3 more16500f Firmware A250 FirmwareActive Iq Unified Manager+13 moreJun 17, 2026 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 developm...Show more |
5Debian FedoraprojectIsc+2 more15Active Iq Unified Manager Aff 500f FirmwareAff A250 Firmware+12 moreJun 17, 2026 Apr 29, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the...Show more |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerContr...Show more |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server...Show more |
3Debian FedoraprojectGetcomposer3Composer Debian LinuxFedoraJun 17, 2026 Apr 27, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot b...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation ca...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbou...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be...Show more |