Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 2, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use After Free in GitHub repository vim/vim prior to 8.2. |
4Debian FedoraprojectPostgresql+1 more4Debian Linux FedoraPostgresql Jdbc Driver+1 moreJun 17, 2026 Feb 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker con...Show more |
2Debian Minetest2Debian Linux MinetestJun 17, 2026 Feb 2, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In Minetest before 5.4.0, players can add or subtract items from a different player's inventory. |
2Debian Minetest2Debian Linux MinetestJun 17, 2026 Feb 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 1, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. |
5Debian FedoraprojectJenkins+2 more11Commerce Guided Search Communications Brm Elastic Charging EngineCommunications Cloud Native Core Automated Test Suite+8 moreJun 17, 2026 Feb 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel exe...Show more |
2Debian Twistedmatrix2Debian Linux TreqJun 17, 2026 Feb 1, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such co...Show more |
3Debian FedoraprojectMariadb3Debian Linux FedoraMariadbJun 17, 2026 Feb 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used. |
4Canonical DebianFedoraproject+1 more5Debian Linux Extra Packages For Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 31, 2022 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authenticatio...Show more |
3Debian FedoraprojectInvisible Island3Debian Linux FedoraXtermJun 17, 2026 Jan 31, 2022 N/A· v4 5.5 MEDIUM· v3 2.6 LOW· v2 xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Jan 30, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use After Free in GitHub repository vim/vim prior to 8.2. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Jan 30, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
3Apple DebianVim3Debian Linux MacosVimJun 17, 2026 Jan 28, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. |
4Debian OpensslOracle+1 more8Debian Linux Enterprise Manager Ops CenterHealth Sciences Inform Publisher+5 moreJun 17, 2026 Jan 28, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites f...Show more |
2Debian Intel2Connman Debian LinuxJun 17, 2026 Jan 28, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received. |
2Debian Intel2Connman Debian LinuxJun 17, 2026 Jan 28, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read. |
2Debian Intel2Connman Debian LinuxJun 17, 2026 Jan 28, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read. |
3Apache DebianOracle7Agile Engineering Data Management Communications Cloud Native Core PolicyDebian Linux+4 moreJun 17, 2026 Jan 27, 2022 N/A· v4 7.0 HIGH· v3 3.7 LOW· v2 The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to...Show more |