Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and...Show more |
2Debian Mozilla3Debian Linux Firefox EsrThunderbirdJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 115.6 and Thunderbird < 115.6. |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 1...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. Th...Show more |
2Debian Mozilla2Debian Linux ThunderbirdJun 17, 2026 Dec 19, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was...Show more |
2Debian Mozilla2Debian Linux ThunderbirdJun 17, 2026 Dec 19, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, an...Show more |
2Debian Openbsd2Debian Linux OpensshJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git...Show more |
2Debian Openbsd2Debian Linux OpensshJul 14, 2026 Dec 18, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only appli...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
2Debian Redhat4Ansible Automation Platform Ansible DeveloperAnsible Inside+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file...Show more |
4Debian RedhatTigervnc+1 more5Debian Linux Enterprise Linux EusTigervnc+2 moreJun 23, 2026 Dec 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information. |
4Debian RedhatTigervnc+1 more5Debian Linux Enterprise Linux EusTigervnc+2 moreJun 23, 2026 Dec 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possibl...Show more |
2Apple Debian7Debian Linux IpadosIphone Os+4 moreJun 17, 2026 Dec 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead...Show more |
3Debian FedoraprojectLibreoffice3Debian Linux FedoraLibreofficeJun 17, 2026 Dec 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar b...Show more |
3Debian FedoraprojectLibreoffice3Debian Linux FedoraLibreofficeJun 17, 2026 Dec 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video...Show more |