Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
4Debian FedoraprojectFrrouting+1 more4Debian Linux FedoraFrrouting+1 moreJun 17, 2026 Aug 29, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation). |
2Debian Frrouting2Debian Linux FrroutingJun 17, 2026 Aug 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version. |
3Debian FedoraprojectFrrouting3Debian Linux FedoraFrroutingJun 17, 2026 Aug 29, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation. |
3Debian FedoraprojectFrrouting3Debian Linux FedoraFrroutingJun 17, 2026 Aug 29, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero. |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Aug 28, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a...Show more |
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid securi...Show more |
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0...Show more |
2Debian Prometheus2Alertmanager Debian LinuxJun 17, 2026 Aug 25, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) |
3Debian NetappPython4Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+1 moreJun 17, 2026 Aug 22, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. |
2Debian Python2Debian Linux PythonJun 17, 2026 Aug 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities. |
A use-after-free exists in Python through 3.9 via heappushpop in heapq. |
2Debian File Project2Debian Linux FileJun 17, 2026 Aug 22, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project. |
2Busybox Debian2Busybox Debian LinuxJul 14, 2026 Aug 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. |
2Apache Debian2Debian Linux Xml Graphics BatikJun 17, 2026 Aug 22, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it dire...Show more |
2Apache Debian2Debian Linux Xml Graphics BatikJun 17, 2026 Aug 22, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading externa...Show more |