Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Jul 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name la...Show more |
3Debian LinuxNetapp3Active Iq Unified Manager Debian LinuxLinux KernelJun 17, 2026 Jun 30, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Jun 28, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 28, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvl...Show more |
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium se...Show more |
Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Artifex DebianFedoraproject3Debian Linux FedoraGhostscriptJun 17, 2026 Jun 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). |
2Debian Shibboleth2Debian Linux XmltoolingJun 17, 2026 Jun 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.) |
5Debian FedoraprojectLinux+2 more9Debian Linux Enterprise LinuxFedora+6 moreJun 17, 2026 Jun 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been fre...Show more |
4Apple DebianFedoraproject+1 more4Cups Debian LinuxFedora+1 moreJun 17, 2026 Jun 22, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging serv...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can b...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 18, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 18, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c. |
4Canonical DebianLinux+1 more8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Jun 16, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 16, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal in...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Jun 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocke...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jun 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |