Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 May 3, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI int...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 May 3, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML p...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 May 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium) |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 26, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to le...Show more |
3Debian LinuxNetapp8Active Iq Unified Manager Debian LinuxH300s Firmware+5 moreJun 17, 2026 Apr 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on...Show more |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s Firmware+5 moreJun 17, 2026 Apr 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. |
3Debian LinuxNetapp8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Apr 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabil...Show more |
2Debian Xmlsoft2Debian Linux Libxml2Jun 17, 2026 Apr 24, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory error...Show more |
2Debian Xmlsoft2Debian Linux Libxml2Jun 17, 2026 Apr 24, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c. |
4Debian FedoraprojectLinux+1 more4Debian Linux FedoraH410c Firmware+1 moreJun 17, 2026 Apr 24, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 21, 2023 N/A· v4 5.6 MEDIUM· v3 N/A· v2 The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least o...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 19, 2023 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sev...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 19, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromiu...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 19, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
2Debian Sqlparse Project2Debian Linux SqlparseJun 17, 2026 Apr 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced b...Show more |
3Debian FedoraprojectRedis3Debian Linux FedoraRedisJun 17, 2026 Apr 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue h...Show more |
3Debian EclipseNetapp6Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+3 moreJun 17, 2026 Apr 18, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cooki...Show more |
3Debian NetappOracle107 Mode Transition Tool Brocade San NavigatorCloud Insights Acquisition Unit+7 moreJun 17, 2026 Apr 18, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; O...Show more |