Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Teluu2Debian Linux PjsipJun 17, 2026 Mar 22, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print...Show more |
6Debian FedoraprojectLinux+3 more30Build Of Quarkus Codeready Linux BuilderCommunications Cloud Native Core Binding Support Function+27 moreJun 17, 2026 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege...Show more |
3Debian FedoraprojectOpenvpn3Debian Linux FedoraOpenvpnJun 17, 2026 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be grant...Show more |
3Debian FedoraprojectParamiko3Debian Linux FedoraParamikoJun 17, 2026 Mar 17, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure. |
2Agendaless Debian2Debian Linux WaitressJun 17, 2026 Mar 17, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Wa...Show more |
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEM...Show more |
A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other...Show more |
2Debian Google2Android Debian LinuxJun 17, 2026 Mar 16, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel |
2Debian Openexr2Debian Linux OpenexrJun 17, 2026 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system avail...Show more |
4Debian FedoraprojectQemu+1 more8Codeready Linux Builder Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Mar 16, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. Th...Show more |
3Debian LinuxNetapp10Active Iq Unified Manager Debian LinuxH300e Firmware+7 moreJun 17, 2026 Mar 16, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access. |
7Debian FedoraprojectMariadb+4 more13500f Firmware A250 FirmwareCloud Volumes Ontap Mediator+10 moreJun 17, 2026 Mar 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic cu...Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 17, 2026 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wil...Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 17, 2026 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wil...Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 17, 2026 Mar 14, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data....Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 17, 2026 Mar 14, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data....Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Mar 14, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. |
3Debian FedoraprojectFishshell3Debian Linux FedoraFishJun 17, 2026 Mar 14, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including runni...Show more |
4Apache DebianFedoraproject+1 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Mar 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior vers...Show more |
5Apache AppleDebian+2 more8Debian Linux Enterprise Manager Ops CenterFedora+5 moreJun 17, 2026 Mar 14, 2022 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52...Show more |