CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectNodejs+2 more5Debian Linux FedoraGraalvm+2 moreJun 17, 2026 Jan 6, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraOpenjpeg+1 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. Th...Show more |
3Debian OracleUclouvain3Debian Linux OpenjpegOutside In TechnologyJun 17, 2026 Jan 5, 2021 N/A· v4 7.8 HIGH· v3 8.3 HIGH· v2 A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highes...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraOpenjpeg+1 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from...Show more |
5Debian FedoraprojectOracle+2 more11Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+8 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraOpenjpeg+1 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greate...Show more |
4Debian FedoraprojectLinux+1 more5Cloud Backup Debian LinuxFedora+2 moreJun 17, 2026 Jan 5, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332. |
5Broadcom DebianFedoraproject+2 more8500f Firmware A250 FirmwareDebian Linux+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jan 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts. |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jan 4, 2021 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path dis...Show more |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Jan 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations. |
2Debian Gssproxy Project2Debian Linux GssproxyJun 17, 2026 Dec 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in quest...Show more |
2Debian Linbit2Csync2 Debian LinuxJun 17, 2026 Dec 30, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as requi...Show more |
2Debian Nokogiri2Debian Linux NokogiriJun 17, 2026 Dec 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are...Show more |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Dec 28, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishand...Show more |
3Debian FedoraprojectWavpack3Debian Linux FedoraWavpackJun 17, 2026 Dec 28, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2,...Show more |
4Debian FasterxmlNetapp+1 more40Agile Plm Application Testing SuiteAutovue+37 moreJun 17, 2026 Dec 27, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org....Show more |
2Debian Td Agent Builder Project2Debian Linux Td Agent BuilderJun 17, 2026 Dec 24, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM. |
2Debian Kovidgoyal2Debian Linux KittyJun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message. |
2Debian Postsrsd Project2Debian Linux PostsrsdJun 17, 2026 Dec 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address. |