Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Blender Debian2Blender Debian LinuxJun 17, 2026 Feb 24, 2022 N/A· v4 5.5 MEDIUM· v3 2.6 LOW· v2 An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19,...Show more |
3Debian NodejsOracle9Debian Linux GraalvmMysql Cluster+6 moreJun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name th...Show more |
3Debian NodejsOracle9Debian Linux GraalvmMysql Cluster+6 moreJun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 24, 2022 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write da...Show more |
3Debian FedoraprojectQemu3Debian Linux FedoraQemuJun 17, 2026 Feb 24, 2022 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or...Show more |
3Debian FedoraprojectQemu3Debian Linux FedoraQemuJun 17, 2026 Feb 24, 2022 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input v...Show more |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and u...Show more |
4Debian LinuxNetapp+1 more13Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+10 moreJun 17, 2026 Feb 24, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload. |
3Audiofile DebianFedoraproject3Audiofile Debian LinuxFedoraJun 17, 2026 Feb 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function cal...Show more |
5Cyrusimap DebianFedoraproject+2 more8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Network Function Cloud Native Environment+5 moreJun 17, 2026 Feb 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. |
3Debian FedoraprojectUsbguard Project3Debian Linux FedoraUsbguardJun 17, 2026 Feb 24, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future. |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 23, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440. |
4Asterisk DebianSangoma+1 more4Asterisk Certified AsteriskDebian Linux+1 moreJun 17, 2026 Feb 22, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a di...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 22, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436. |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Feb 21, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outa...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 21, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428. |
6Canonical DebianFedoraproject+3 more23Codeready Linux Builder Debian LinuxDiskstation Manager+20 moreJun 17, 2026 Feb 21, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 20, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive informatio...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 20, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418. |
duck before 0.10 did not properly handle loading of untrusted code from the current directory. |