Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cr...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cra...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craf...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Mar 1, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. |
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Feb 25, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device. |
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges. |
5Debian FedoraprojectHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potent...Show more |
2Debian Mono Project2Debian Linux MonoJun 17, 2026 Feb 22, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter. |
2Debian Libreswan2Debian Linux LibreswanJun 17, 2026 Feb 21, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length. |
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags progra...Show more |
2Apache Debian2Commons Fileupload Debian LinuxJun 17, 2026 Feb 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, li...Show more |
5Debian FedoraprojectGnu+2 more7Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+4 moreJun 17, 2026 Feb 15, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbache...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Feb 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in...Show more |
2Debian Haproxy2Debian Linux HaproxyJun 17, 2026 Feb 14, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names,...Show more |
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2. |
A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via ex...Show more |