CVEs (117)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache AppleDebian+2 more8Debian Linux Enterprise Manager Ops CenterFedora+5 moreNov 21, 2024 Mar 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling |
5Apache AppleDebian+2 more7Debian Linux FedoraHttp Server+4 moreNov 21, 2024 Mar 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreNov 25, 2024 Mar 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version iden...Show more |
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreMay 5, 2025 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreNov 21, 2024 Feb 21, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outa...Show more |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreMay 5, 2025 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreMay 5, 2025 Feb 18, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreMay 30, 2025 Feb 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element. |
4Debian Libexpat ProjectOracle+1 more5Debian Linux Http ServerLibexpat+2 moreMay 5, 2025 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreMay 5, 2025 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. |
4Fedoraproject NetappOracle+1 more10Active Iq Unified Manager FedoraHci+7 moreDec 17, 2025 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input...Show more |
7Canonical OraclePolkit Project+4 more30Command Center Enterprise LinuxEnterprise Linux Desktop+27 moreNov 6, 2025 Jan 28, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic...Show more |
1Oracle 3Http Server SolarisZfs Storage Appliance KitNov 21, 2024 Jan 19, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastru...Show more |
2Netapp Oracle197 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+16 moreNov 21, 2024 Jan 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Ente...Show more |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreNov 3, 2025 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreNov 3, 2025 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
3Fedoraproject OracleWireshark4Fedora Http ServerWireshark+1 moreNov 21, 2024 Dec 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file |
3Fedoraproject OracleWireshark4Fedora Http ServerWireshark+1 moreNov 3, 2025 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreNov 3, 2025 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
7Apache AppleDebian+4 more14Cloud Backup Communications Element ManagerCommunications Operations Monitor+11 moreMay 1, 2025 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might...Show more |