Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectNetapp+2 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 3, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user in...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user in...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user in...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user in...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application den...Show more |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions. |
2Debian Sinatrarb2Debian Linux SinatraJun 17, 2026 May 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. |
4Debian GoogleNetapp+1 more6Active Iq Unified Manager Debian LinuxFinancial Services Crime And Compliance Management Studio+3 moreJun 17, 2026 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
3Debian QemuRedhat3Debian Linux Enterprise LinuxQemuJun 17, 2026 Apr 29, 2022 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a...Show more |
3Debian QemuRedhat3Debian Linux Enterprise LinuxQemuJun 17, 2026 Apr 29, 2022 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. Th...Show more |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreJun 17, 2026 Apr 29, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of intern...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 29, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detache...Show more |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreJun 17, 2026 Apr 29, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. T...Show more |
3Debian FedoraprojectSamba3Cifs Utils Debian LinuxFedoraJun 17, 2026 Apr 28, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file. |
5Debian FedoraprojectHp+2 more19Caas Platform Cifs UtilsDebian Linux+16 moreJun 17, 2026 Apr 27, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. |
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it alloc...Show more |
2Debian Teluu2Debian Linux PjsipJun 17, 2026 Apr 25, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV fi...Show more |
2Artifex Debian2Debian Linux GhostscriptJun 17, 2026 Apr 25, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 22, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race conditi...Show more |