Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectMozilla5Debian Linux FedoraFirefox+2 moreJun 17, 2026 Sep 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox <...Show more |
3Debian FedoraprojectMozilla5Debian Linux FedoraFirefox+2 moreJun 17, 2026 Sep 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Fi...Show more |
3Apple DebianFedoraproject8Debian Linux FedoraIpados+5 moreJun 17, 2026 Sep 27, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution. |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Sep 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitraril...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Sep 25, 2023 N/A· v4 9.0 CRITICAL· v3 N/A· v2 Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become a...Show more |
3Debian LinuxXen3Debian Linux Linux KernelXenJun 17, 2026 Sep 22, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that not all of the headers would come in one piece. Unfortunately the logic introduced there didn't ac...Show more |
2Debian Roundcube2Debian Linux WebmailJun 17, 2026 Sep 22, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. |
3Debian FedoraprojectOpenprinting4Cups Debian LinuxFedora+1 moreJun 17, 2026 Sep 21, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in C...Show more |
6Apple DebianFedoraproject+3 more14Active Iq Unified Manager Cloud Insights Acquisition UnitCloud Insights Storage Workload Security Agent+11 moreJun 17, 2026 Sep 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploit...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Sep 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the ke...Show more |
2Debian Reportlab2Debian Linux ReportlabJun 17, 2026 Sep 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by a...Show more |
4Debian FedoraprojectIsc+1 more8Bind Debian LinuxFedora+5 moreJun 17, 2026 Sep 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS...Show more |
3Debian FedoraprojectIsc3Bind Debian LinuxFedoraJun 17, 2026 Sep 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environmen...Show more |
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, a...Show more |
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more per...Show more |
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 12, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 12, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 12, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 12, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) |