CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian LinuxNetapp12Cloud Backup Debian LinuxH300e Firmware+9 moreJun 17, 2026 Apr 19, 2021 N/A· v4 7.1 HIGH· v3 5.6 MEDIUM· v2 An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds m...Show more |
4Debian GstreamerGstreamer Project+1 more4Debian Linux Enterprise LinuxGstreamer+1 moreJun 17, 2026 Apr 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. |
4Debian GstreamerGstreamer Project+1 more4Debian Linux Enterprise LinuxGstreamer+1 moreJun 17, 2026 Apr 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files. |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Apr 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is...Show more |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Apr 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is trig...Show more |
2Debian Ezxml Project2Debian Linux EzxmlJun 17, 2026 Apr 16, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure). |
2Debian Ezxml Project2Debian Linux EzxmlJun 17, 2026 Apr 16, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (writing outside a memory region created by mmap). |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 15, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched i...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 15, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP...Show more |
2Debian Ezxml Project2Debian Linux EzxmlJun 17, 2026 Apr 15, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant. |
4Debian FedoraprojectLinuxfoundation+1 more4Ceph Ceph StorageDebian Linux+1 moreJun 17, 2026 Apr 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_...Show more |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 Apr 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1...Show more |
3Debian LinuxStarwindsoftware3Debian Linux Linux KernelStarwind Virtual SanJun 17, 2026 Apr 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: t...Show more |
4Apache DebianNetapp+1 more60Access Manager Active Iq Unified ManagerAgile Engineering Data Management+57 moreJun 17, 2026 Apr 13, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files...Show more |
2Debian Ezxml Project2Debian Linux EzxmlJun 17, 2026 Apr 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory handling, leading to a NULL pointer dereference while running strcmp()...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget(...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently hav...Show more |
4Debian Exiv2Fedoraproject+1 more4Debian Linux Enterprise LinuxExiv2+1 moreJun 17, 2026 Apr 8, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a cra...Show more |
4Debian FedoraprojectLinux+1 more13Cloud Backup Debian LinuxFedora+10 moreJun 17, 2026 Apr 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and ar...Show more |