CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectLinux+1 more8Cloud Backup Debian LinuxFedora+5 moreJun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failu...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Feb 17, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encounter...Show more |
7Apple DebianNetapp+4 more23Business Intelligence Communications Cloud Native Core PolicyDebian Linux+20 moreJun 17, 2026 Feb 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle a...Show more |
7Debian FujitsuMcafee+4 more21Business Intelligence Communications Cloud Native Core PolicyDebian Linux+18 moreJun 17, 2026 Feb 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. I...Show more |
2Debian Mumble2Debian Linux MumbleJun 17, 2026 Feb 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text. |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could poten...Show more |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing u...Show more |
6Debian DjangoprojectFedoraproject+3 more12Cloud Backup Communications Offline Mediation ControllerCommunications Pricing Design Center+9 moreJun 17, 2026 Feb 15, 2021 N/A· v4 5.9 MEDIUM· v3 4.0 MEDIUM· v2 The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.pars...Show more |
4Debian NetappOracle+1 more4Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+1 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause...Show more |
3Debian NetappPhp3Clustered Data Ontap Debian LinuxPhpJun 17, 2026 Feb 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to...Show more |
2Debian Horde2Debian Linux GroupwareJun 17, 2026 Feb 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a li...Show more |
2Debian Openldap2Debian Linux OpenldapJun 17, 2026 Feb 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short t...Show more |
2Adminer Debian2Adminer Debian LinuxJun 17, 2026 Feb 11, 2021 N/A· v4 7.2 HIGH· v3 6.4 MEDIUM· v2 Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g...Show more |
3Debian FedoraprojectOpenvswitch3Debian Linux FedoraOpenvswitchJun 17, 2026 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be to...Show more |
3Debian FedoraprojectGoogle3Android Debian LinuxFedoraJun 17, 2026 Feb 10, 2021 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no addition...Show more |
3Debian FedoraprojectInvisible Island3Debian Linux FedoraXtermJun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence. |
2Debian Genivi2Debian Linux Diagnostic Log And TraceJun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6). |
3Debian FedoraprojectGnu3Debian Linux FedoraScreenJun 17, 2026 Feb 9, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence. |
3Debian IntelOpensuse3Connman Debian LinuxLeapJun 17, 2026 Feb 9, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp. |