Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Asterisk DebianSangoma+1 more4Asterisk Certified AsteriskDebian Linux+1 moreJun 17, 2026 Dec 22, 2021 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message c...Show more |
5Debian FedoraprojectLinux+2 more12Debian Linux Enterprise LinuxFedora+9 moreJun 17, 2026 Dec 22, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. |
7Apache AppleDebian+4 more14Cloud Backup Communications Element ManagerCommunications Operations Monitor+11 moreJun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might...Show more |
6Apache AppleDebian+3 more12Communications Element Manager Communications Operations MonitorCommunications Session Report Manager+9 moreJun 17, 2026 Dec 20, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. |
5Apache DebianNetapp+2 more1166bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+113 moreJun 17, 2026 Dec 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t...Show more |
3Debian LinuxfoundationOracle5Communications Policy Management Debian LinuxDojo+2 moreJun 17, 2026 Dec 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentialit...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confident...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data c...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confid...Show more |
2Debian Oisf2Debian Linux SuricataJun 17, 2026 Dec 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way han...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 16, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Vis...Show more |
5Debian FedoraprojectGnu+2 more5Binutils Debian LinuxEnterprise Linux+2 moreJun 17, 2026 Dec 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds wr...Show more |
3Debian GoogleLinux3Android Debian LinuxLinux KernelJun 17, 2026 Dec 15, 2021 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...Show more |
2Debian Itextpdf2Debian Linux ItextJun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java. |