Debian
debian
10,145 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. |
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. |
2Debian Mplayerhq3Debian Linux MencoderMplayerJun 17, 2026 Sep 15, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. |
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow inje...Show more |
3Debian FedoraprojectLibexpat Project3Debian Linux FedoraLibexpatJun 17, 2026 Sep 14, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. |
2Debian Lighttpd2Debian Linux LighttpdJun 17, 2026 Sep 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be use...Show more |
3Debian LeptonicaTesseract Project3Debian Linux LeptonicaTesseractJun 17, 2026 Sep 9, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Sep 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_IOCTL_RESET and the NVME_IOCTL_SUBSYS_RESET through the device file of the driver, resulting in a PCI...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a lo...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Sep 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unau...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 9, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free. |
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin. |
Use After Free in GitHub repository vim/vim prior to 9.0.0389. |
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authe...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlJun 17, 2026 Sep 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlJun 17, 2026 Sep 5, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Snakeyaml Project2Debian Linux SnakeyamlJun 17, 2026 Sep 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack...Show more |
2Debian Tinygltf Project2Debian Linux TinygltfJun 17, 2026 Sep 5, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attack...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 5, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing th...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 3, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0360. |