Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectLinux+1 more9Active Iq Unified Manager Debian LinuxFedora+6 moreJun 17, 2026 Feb 16, 2022 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability. |
6Debian FedoraprojectLinux+3 more193scale Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+16 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.1 HIGH· v3 7.9 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or...Show more |
3Debian FedoraprojectIsync Project3Debian Linux FedoraIsyncJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an u...Show more |
4Canonical DebianPolkit Project+1 more6Debian Linux Openshift Container PlatformPolkit+3 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to,...Show more |
3Debian FedoraprojectKicad3Debian Linux EdaFedoraJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or exce...Show more |
3Debian FedoraprojectKicad3Debian Linux EdaFedoraJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or exce...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 16, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the...Show more |
4Debian Libexpat ProjectOracle+1 more5Debian Linux Http ServerLibexpat+2 moreJun 17, 2026 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 14, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
4Apple DebianFedoraproject+1 more5Debian Linux FedoraMac Os X+2 moreJun 17, 2026 Feb 14, 2022 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion. |
4Debian FedoraprojectPuma+1 more4Debian Linux FedoraPuma+1 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being close...Show more |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Feb 11, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` w...Show more |
2Debian Skolelinux2Debian Edu Config Debian LinuxJun 17, 2026 Feb 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privile...Show more |
4Debian FedoraprojectLibtiff+1 more4Debian Linux FedoraLibtiff+1 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compi...Show more |