Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0...Show more |
2Cloudbase Debian2Debian Linux Open VswitchJun 17, 2026 Sep 28, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of c...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 27, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 27, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member o...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via...Show more |
3Debian FedoraprojectJoblib Project3Debian Linux FedoraJoblibJun 17, 2026 Sep 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement. |
3Debian FedoraprojectNic3Debian Linux FedoraKnot ResolverJun 17, 2026 Sep 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets. |
5Apple DebianHaxx+2 more13Bootstrap Os Clustered Data OntapCurl+10 moreJun 17, 2026 Sep 23, 2022 N/A· v4 3.7 LOW· v3 N/A· v2 When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing...Show more |
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. |
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14. |
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14. |
3Debian FedoraprojectGoogle4Debian Linux FedoraProtobuf Cpp+1 moreJun 17, 2026 Sep 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17....Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 22, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0530. |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
3Debian FedoraprojectIsc3Bind Debian LinuxFedoraJun 17, 2026 Sep 21, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service. |
4Canonical DebianLinux+1 more4Debian Linux Hci Baseboard Management ControllerLinux Kernel+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 21, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release. |
3Apple DebianFedoraproject5Debian Linux FedoraIpados+2 moreJun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution. |
In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls. |