CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control via malicious network traffic. |
2Fedoraproject Redhat3Ceph Ceph StorageFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible. |
5Debian FedoraprojectNodejs+2 more5Debian Linux FedoraGraalvm+2 moreJun 17, 2026 Jan 6, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field...Show more |
5Debian FedoraprojectNodejs+2 more5Debian Linux FedoraGraalvm+2 moreJun 17, 2026 Jan 6, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraOpenjpeg+1 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. Th...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraOpenjpeg+1 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from...Show more |
5Debian FedoraprojectOracle+2 more11Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+8 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraOpenjpeg+1 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greate...Show more |
4Debian FedoraprojectLinux+1 more5Cloud Backup Debian LinuxFedora+2 moreJun 17, 2026 Jan 5, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332. |
5Broadcom DebianFedoraproject+2 more8500f Firmware A250 FirmwareDebian Linux+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jan 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts. |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jan 4, 2021 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path dis...Show more |
4Broadcom FedoraprojectGnu+1 more8Binutils Brocade Fabric Operating System FirmwareCloud Backup+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest thre...Show more |
4Broadcom FedoraprojectGnu+1 more8Binutils Brocade Fabric Operating System FirmwareCloud Backup+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to applic...Show more |
4Broadcom FedoraprojectGnu+1 more8Binutils Brocade Fabric Operating System FirmwareCloud Backup+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availabi...Show more |
4Broadcom FedoraprojectGnu+1 more8Binutils Brocade Fabric Operating System FirmwareCloud Backup+5 moreJun 17, 2026 Jan 4, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application av...Show more |