Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Nlnetlabs2Debian Linux RoutinatorJun 17, 2026 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively s...Show more |
2Debian Fort Validator Project2Debian Linux Fort ValidatorJun 17, 2026 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Or...Show more |
3Debian FedoraprojectGolang3Debian Linux FedoraGoJun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation. |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Nov 5, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 vim is vulnerable to Use of Uninitialized Variable |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Nov 5, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
2Bluez Debian2Bluez Debian LinuxJun 17, 2026 Nov 4, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call. |
4Debian LinuxOracle+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Nov 4, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. |
3Debian LlhttpOracle3Debian Linux GraalvmLlhttpJun 17, 2026 Nov 3, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. |
2Debian Htmldoc Project2Debian Linux HtmldocJun 17, 2026 Nov 3, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Nov 3, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Nov 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Nov 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Nov 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. |
2Debian Mozilla2Debian Linux ThunderbirdJun 17, 2026 Nov 3, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Nov 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Nov 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbir...Show more |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Nov 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Nov 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Nov 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |