Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Mar 30, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Specia...Show more |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 Mar 29, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory,...Show more |
2Debian Long Range Zip Project2Debian Linux Long Range ZipJun 17, 2026 Mar 28, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a cr...Show more |
2Clusterlabs Debian2Debian Linux PcsJun 17, 2026 Mar 25, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accoun...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Mar 25, 2022 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO)...Show more |
4Debian FedoraprojectOpenexr+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not...Show more |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Mar 25, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application s...Show more |
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious gu...Show more |
11Apple AzulDebian+8 more27Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+24 moreJul 14, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
4Debian FedoraprojectLinuxfoundation+1 more4Debian Linux FedoraMoby+1 moreJun 17, 2026 Mar 24, 2022 N/A· v4 5.9 MEDIUM· v3 4.6 MEDIUM· v2 Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-em...Show more |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Mar 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Mar 23, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space. |
5Broadcom DebianLinux+2 more9Brocade Fabric Operating System Firmware Communications Cloud Native Core Binding Support FunctionDebian Linux+6 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have...Show more |
2Debian Libsndfile Project2Debian Linux LibsndfileJun 17, 2026 Mar 23, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfil...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Mar 23, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) du...Show more |
5Canonical DebianFedoraproject+2 more6Debian Linux Enterprise LinuxEnterprise Linux Advanced Virtualization Eus+3 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 6.9 MEDIUM· v2 A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has b...Show more |
5Debian F5Fedoraproject+2 more5Debian Linux FedoraNginx+2 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Mar 23, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. |
5Debian FedoraprojectLinux+2 more13Debian Linux Enterprise LinuxFedora+10 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause...Show more |