Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams f...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment...Show more |
5Canonical DebianLinux+2 more9Debian Linux Enterprise LinuxH300s Firmware+6 moreJun 17, 2026 Mar 27, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than th...Show more |
3Debian LinuxNetapp128300 Firmware 8700 FirmwareA400 Firmware+9 moreJun 17, 2026 Mar 27, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type conf...Show more |
3Debian DinoFedoraproject3Debian Linux DinoFedoraJun 17, 2026 Mar 24, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a g...Show more |
4Canonical DebianLinux+1 more8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Mar 22, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Mar 21, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests wi...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Mar 21, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests wi...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Mar 21, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow m...Show more |
3Debian LinuxNetapp7Debian Linux H300sH410c+4 moreJun 17, 2026 Mar 16, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference). |
A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing t...Show more |
3Apache DebianUnbit3Debian Linux Http ServerUwsgiJun 17, 2026 Mar 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the...Show more |
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free. |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Mar 6, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file |
debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.) |
3Debian LinuxfoundationRedhat4Debian Linux Enterprise LinuxOpenshift Container Platform+1 moreJun 17, 2026 Mar 3, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount con...Show more |
2Debian Systemd Project2Debian Linux SystemdJun 17, 2026 Mar 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not...Show more |
Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc. |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cra...Show more |