Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte ran...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded fo...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-en...Show more |
2Debian Frrouting2Debian Linux FrroutingJun 17, 2026 Sep 19, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c. |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Sep 19, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Sep 19, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0490. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Sep 18, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 17, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 16, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is...Show more |
2Debian Jettison Project2Debian Linux JettisonJun 17, 2026 Sep 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to cra...Show more |
2Debian Jettison Project2Debian Linux JettisonJun 17, 2026 Sep 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to cra...Show more |
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. |
2Debian Mplayerhq2Debian Linux MencoderJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c. |
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. |
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. |
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1. |
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-...Show more |
2Debian Mplayerhq2Debian Linux MplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c. |