Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 30, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to g...Show more |
2Debian Lemonldap Ng2Apache\ Debian LinuxJun 17, 2026 Jan 27, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is use...Show more |
2Debian Lemonldap Ng2Apache\ Debian LinuxJun 17, 2026 Jan 27, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE:...Show more |
2Debian Openstack4Cinder Debian LinuxGlance+1 moreJun 17, 2026 Jan 26, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a spec...Show more |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Jan 26, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file |
2Debian Libtiff2Debian Linux LibtiffJun 17, 2026 Jan 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image. |
2Debian Html Stripscripts Project2Debian Linux Html StripscriptsJun 17, 2026 Jan 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes. |
2Debian Trustwave2Debian Linux ModsecurityJun 17, 2026 Jan 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_...Show more |
3Debian OwaspTrustwave3Debian Linux ModsecurityModsecurityJun 17, 2026 Jan 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent c...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries...Show more |
2Debian Openstack2Debian Linux SwiftJun 17, 2026 Jan 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that...Show more |
3Debian FedoraprojectRuby Git Project3Debian Linux FedoraRuby GitJun 17, 2026 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
2Debian Ruby Git Project2Debian Linux Ruby GitJun 17, 2026 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
3Debian FedoraprojectTorproject3Debian Linux FedoraTorJun 17, 2026 Jan 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002. |
3Debian LinuxNetapp3Debian Linux Hci Baseboard Management ControllerLinux KernelJun 17, 2026 Jan 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition. |
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_AC...Show more |
2Debian Openvswitch2Debian Linux OpenvswitchJun 17, 2026 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. |