Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Debian2Commons Net Debian LinuxJun 17, 2026 Dec 3, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the maliciou...Show more |
2Debian G810 Led Project2Debian Linux G810 LedJun 17, 2026 Nov 30, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, i...Show more |
2Debian Sinatrarb2Debian Linux SinatraJun 17, 2026 Nov 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attac...Show more |
3Debian FedoraprojectGnu3Debian Linux EmacsFedoraJun 17, 2026 Nov 28, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags progra...Show more |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s Firmware+5 moreJun 17, 2026 Nov 27, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. |
3Debian OpenjsfQs Project3Debian Linux ExpressQsJun 17, 2026 Nov 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an...Show more |
3Artifex DebianFedoraproject3Debian Linux FedoraMujsJun 17, 2026 Nov 23, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file...Show more |
2Debian Postgresql2Debian Linux Postgresql Jdbc DriverJun 17, 2026 Nov 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a tempora...Show more |
4Debian FedoraprojectLibarchive+1 more4Debian Linux FedoraLibarchive+1 moreJun 17, 2026 Nov 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the...Show more |
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the se...Show more |
2Debian Heimdal Project2Debian Linux HeimdalJun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) a...Show more |
4Apple DebianLibtiff+1 more7Active Iq Unified Manager Debian LinuxIpados+4 moreJun 17, 2026 Nov 13, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to in...Show more |
3Debian FedoraprojectNetatalk3Debian Linux FedoraNetatalkJun 17, 2026 Nov 12, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS). |
3Debian FedoraprojectXfce3Debian Linux FedoraXfce4 SettingsJun 17, 2026 Nov 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper. |
4Debian FedoraprojectVarnish Software+1 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in th...Show more |
Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch...Show more |
Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |