Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GstreamerGstreamer Project3Debian Linux GstreamerGstreamerJun 17, 2026 Jul 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chun...Show more |
3Debian GstreamerGstreamer Project3Debian Linux GstreamerGstreamerJun 17, 2026 Jul 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc...Show more |
3Debian GstreamerGstreamer Project3Debian Linux GstreamerGstreamerJun 17, 2026 Jul 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwrite, depending on lib...Show more |
3Debian GstreamerGstreamer Project3Debian Linux GstreamerGstreamerJun 17, 2026 Jul 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depend...Show more |
3Debian GstreamerGstreamer Project3Debian Linux GstreamerGstreamerJun 17, 2026 Jul 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite. |
3Debian GstreamerGstreamer Project3Debian Linux GstreamerGstreamerJun 17, 2026 Jul 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite. |
6Apache AzulDebian+3 more167 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+13 moreJun 17, 2026 Jul 19, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execut...Show more |
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client |
3Debian LinuxOpenatom3Debian Linux Linux KernelOpeneulerJun 17, 2026 Jul 18, 2022 N/A· v4 6.8 MEDIUM· v3 N/A· v2 When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 18, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. |
2Debian Lemonldap Ng2Debian Linux Lemonldap\Jun 17, 2026 Jul 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos...Show more |
2Debian Lemonldap Ng2Debian Linux Lemonldap\Jun 17, 2026 Jul 18, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl...Show more |
2Debian Squid Cache2Debian Linux SquidJun 17, 2026 Jul 17, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses. |
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Jul 15, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-re...Show more |
4Amd DebianFedoraproject+1 more126A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+123 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. |
6Debian FedoraprojectLlhttp+3 more6Debian Linux FedoraLlhttp+3 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). |
4Debian LlhttpNodejs+1 more4Debian Linux LlhttpNode.js+1 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). |
6Debian FedoraprojectLlhttp+3 more6Debian Linux FedoraLlhttp+3 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). |
4Debian FedoraprojectNodejs+1 more4Debian Linux FedoraNode.js+1 moreJun 17, 2026 Jul 14, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP addr...Show more |