Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Nov 19, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 vim is vulnerable to Heap-based Buffer Overflow |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Nov 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Use After Free |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Nov 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Nov 19, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message. |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Nov 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file |
5Debian FedoraprojectLinux+2 more15Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+12 moreJun 17, 2026 Nov 17, 2021 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). |
4Debian FedoraprojectLinux+1 more11Cloud Backup Debian LinuxFedora+8 moreJun 17, 2026 Nov 17, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a...Show more |
3Debian LlhttpOracle3Debian Linux GraalvmLlhttpJun 17, 2026 Nov 15, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6. |
3Debian GmplibNetapp8Active Iq Unified Manager Debian LinuxGmp+5 moreJun 17, 2026 Nov 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms. |
2Debian Json Schema Project2Debian Linux Json SchemaJun 17, 2026 Nov 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
2Bluez Debian2Bluez Debian LinuxJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be fre...Show more |
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attac...Show more |
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Nov 12, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash). |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character). |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the con...Show more |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the bas...Show more |
2Debian Nlnetlabs2Debian Linux RoutinatorJun 17, 2026 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in thes...Show more |