Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd d...Show more |
3Debian FedoraprojectYardoc3Debian Linux FedoraYardJun 17, 2026 Feb 28, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScri...Show more |
3Debian FedoraprojectFontforge3Debian Linux FedoraFontforgeJun 17, 2026 Feb 26, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. |
3Debian FedoraprojectFontforge3Debian Linux FedoraFontforgeJun 17, 2026 Feb 26, 2024 N/A· v4 4.2 MEDIUM· v3 N/A· v2 Splinefont in FontForge through 20230101 allows command injection via crafted filenames. |
3Debian EclipseNetapp4Active Iq Unified Manager BluexpDebian Linux+1 moreJun 17, 2026 Feb 26, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and th...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 23, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racin...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 22, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 20, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts()....Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115....Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-C...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently g...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Fire...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox E...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR <...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thun...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 20, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added i...Show more |
3Canonical DebianTianocore3Debian Linux Edk2LxdJun 17, 2026 Feb 14, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. |
6Debian FedoraprojectIsc+3 more8Active Iq Unified Manager BindBootstrap Os+5 moreJun 17, 2026 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in...Show more |
3Debian FedoraprojectOpenidc3Debian Linux FedoraMod Auth OpenidcJun 17, 2026 Feb 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validatio...Show more |