Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. |
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115....Show more |
In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability...Show more |
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR <...Show more |
5Debian FedoraprojectLinux+2 more8Debian Linux Enterprise LinuxFedora+5 moreJun 17, 2026 Jul 31, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jul 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRE...Show more |
4Debian FedoraprojectLinux+1 more6Debian Linux Enterprise LinuxEnterprise Linux For Real Time+3 moreJun 17, 2026 Jul 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_...Show more |
Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via the --extract-media option or outputting to PDF format. This allows an at...Show more |
3Amd DebianXen71Athlon Gold 7220u Firmware Debian LinuxEpyc 7232p Firmware+68 moreJun 17, 2026 Jul 24, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 24, 2023 N/A· v4 4.1 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue. |
2Debian Mozilla2Debian Linux ThunderbirdJun 17, 2026 Jul 24, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunder...Show more |
3Debian FedoraprojectGnome3Debian Linux FedoraLibrsvgJun 17, 2026 Jul 22, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?.....Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 21, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, fw_set_parms() will immediately return an error after...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 21, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bound...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 21, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Flaw in the error handling of bound chains causes a use-after-free in the abort...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 21, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error aft...Show more |
4Debian FedoraprojectRedhat+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character str...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a fiel...Show more |