CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectLxml+2 more5Debian Linux FedoraLxml+2 moreJun 17, 2026 Mar 21, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Mar 20, 2021 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-cha...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Mar 20, 2021 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and o...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Mar 20, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1. |
3Debian FedoraprojectKramdown Project3Debian Linux FedoraKramdownJun 17, 2026 Mar 19, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. |
3Busybox DebianFedoraproject3Busybox Debian LinuxFedoraJun 17, 2026 Mar 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data. |
4Debian FedoraprojectNetapp+1 more4Cloud Manager Debian LinuxFedora+1 moreJun 17, 2026 Mar 19, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security...Show more |
2Debian Python2Debian Linux PillowJun 17, 2026 Mar 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size. |
4Debian GaleraclusterMariadb+1 more4Debian Linux MariadbPercona Server+1 moreJun 17, 2026 Mar 19, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for...Show more |
4Debian FedoraprojectQemu+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 18, 2021 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A...Show more |
4Debian FedoraprojectLinux+1 more12Cloud Backup Debian LinuxFedora+9 moreJun 17, 2026 Mar 17, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not...Show more |
3Debian FedoraprojectPygments3Debian Linux FedoraPygmentsJun 17, 2026 Mar 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to...Show more |
2Apache Debian2Debian Linux SubversionJun 17, 2026 Mar 17, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead...Show more |
The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less users even if they are connected by non-phy...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian OracleWireshark3Debian Linux WiresharkZfs Storage ApplianceJun 17, 2026 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file. |
1Debian 2Courier Authlib Debian LinuxJun 17, 2026 Mar 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a c...Show more |
2Debian Xmldom Project2Debian Linux XmldomJun 17, 2026 Mar 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly p...Show more |