Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In emulation_proc_handler of armv8_deprecated.c, there is a possible way to corrupt memory due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User in...Show more |
In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 11, 2022 N/A· v4 5.6 MEDIUM· v3 N/A· v2 lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two co...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 11, 2022 N/A· v4 3.8 LOW· v3 N/A· v2 Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage pa...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 11, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate pre...Show more |
2Debian Xmldom Project2Debian Linux XmldomJun 17, 2026 Oct 11, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Oct 8, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds...Show more |
3Debian FedoraprojectIsc3Debian Linux DhcpFedoraJun 17, 2026 Oct 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run ou...Show more |
3Debian FedoraprojectIsc3Debian Linux DhcpFedoraJun 17, 2026 Oct 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding...Show more |
2Debian Hsqldb2Debian Linux Hypersql DatabaseJun 17, 2026 Oct 6, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static metho...Show more |
4Debian FasterxmlNetapp+1 more4Debian Linux Jackson DatabindOncommand Workflow Automation+1 moreJun 17, 2026 Oct 2, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only...Show more |
4Debian FasterxmlNetapp+1 more4Debian Linux Jackson DatabindOncommand Workflow Automation+1 moreJun 17, 2026 Oct 2, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGL...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 30, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in p...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 30, 2022 N/A· v4 4.2 MEDIUM· v3 N/A· v2 drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition betwe...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 29, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0614. |
2Debian Ruby Lang2Debian Linux RubyNov 21, 2024 Sep 29, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Special...Show more |
3Debian FedoraprojectPhp3Debian Linux FedoraPhpJun 17, 2026 Sep 28, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie...Show more |
3Debian FedoraprojectPhp3Debian Linux FedoraPhpJun 17, 2026 Sep 28, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickJun 17, 2026 Sep 28, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 In GraphicsMagick, a heap buffer overflow was found when parsing MIFF. |
4Debian DrupalFedoraproject+1 more4Debian Linux DrupalFedora+1 moreJun 17, 2026 Sep 28, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possi...Show more |