Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectRedhat+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreJun 17, 2026 Jan 18, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server wa...Show more |
3Debian NetappOracle9Cloud Insights Acquisition Unit Cloud Insights Storage Workload Security AgentDebian Linux+6 moreJun 17, 2026 Jan 16, 2024 N/A· v4 7.4 HIGH· v3 N/A· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf,...Show more |
3Debian NetappOracle8Cloud Insights Acquisition Unit Cloud Insights Storage Workload Security AgentDebian Linux+5 moreJun 17, 2026 Jan 16, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf...Show more |
3Debian NetappOracle8Cloud Insights Acquisition Unit Cloud Insights Storage Workload Security AgentDebian Linux+5 moreJun 17, 2026 Jan 16, 2024 N/A· v4 7.4 HIGH· v3 N/A· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf,...Show more |
4Debian FedoraprojectGnu+1 more4Active Iq Unified Manager Debian LinuxFedora+1 moreJun 17, 2026 Jan 16, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This fla...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard aga...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 11, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 11, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 11, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition. |
3Debian FedoraprojectJnunemaker3Debian Linux FedoraHttpartyJul 14, 2026 Jan 4, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could resu...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jan 4, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the...Show more |
3Debian FedoraprojectJmcnamara3Debian Linux FedoraSpreadsheet\Jun 17, 2026 Dec 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file in...Show more |
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer ov...Show more |
3Debian EximFedoraproject4Debian Linux EximExtra Packages For Enterprise Linux+1 moreJun 17, 2026 Dec 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing byp...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 19, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 19, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of...Show more |
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability...Show more |
2Debian Mozilla3Debian Linux FirefoxFirefox EsrJun 17, 2026 Dec 19, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click...Show more |
2Debian Mozilla3Debian Linux FirefoxFirefox EsrJun 17, 2026 Dec 19, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability a...Show more |