Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There ar...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function....Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() f...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open(...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no know...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are n...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 7, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced anothe...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 7, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced anothe...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to b...Show more |
2Debian Videolan2Debian Linux Vlc Media PlayerJun 17, 2026 Dec 6, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code u...Show more |
3Debian FedoraprojectGitpython Project3Debian Linux FedoraGitpythonJun 17, 2026 Dec 6, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting...Show more |
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if...Show more |
4Debian LlhttpNodejs+1 more4Debian Linux LlhttpNode.js+1 moreJun 17, 2026 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. |
3Debian NodejsSiemens3Debian Linux Node.jsSinec InsJun 17, 2026 Dec 5, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does...Show more |
5Apple DebianHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Dec 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was us...Show more |
2Debian Rack Project2Debian Linux RackJun 17, 2026 Dec 5, 2022 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack. |
A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack. |
3Awstats DebianFedoraproject3Awstats Debian LinuxFedoraJun 17, 2026 Dec 4, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks. |