Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian NetappNetty+2 more19Banking Apis Banking Digital ExperienceCoherence+16 moreJun 17, 2026 Oct 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The...Show more |
3Apple DebianFedoraproject8Debian Linux FedoraIpados+5 moreJun 17, 2026 Oct 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Oct 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
4Debian FedoraprojectSiemens+1 more25Cp 1543 1 Firmware Debian LinuxFedora+22 moreJun 17, 2026 Oct 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The...Show more |
4Debian FedoraprojectSiemens+1 more206gk5615 0aa00 2aa2 Firmware 6gk5804 0ap00 2aa2 Firmware6gk5812 1aa00 2aa2 Firmware+17 moreJun 17, 2026 Oct 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an ini...Show more |
3Bestpractical DebianFedoraproject3Debian Linux FedoraRequest TrackerJun 17, 2026 Oct 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm. |
3Debian FedoraprojectStb Project3Debian Linux FedoraStbJun 17, 2026 Oct 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file. |
4Apache DebianNetapp+1 more18Agile Engineering Data Management Big Data Spatial And GraphCommunications Diameter Signaling Router+15 moreJun 17, 2026 Oct 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade conne...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 Oct 13, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the...Show more |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Oct 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter. |
3Debian NetappSamba5Debian Linux Management Services For Element SoftwareManagement Services For Netapp Hci+2 moreJun 17, 2026 Oct 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. |
Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma` with a proxy which forwards HTTP header values which contain the LF character could allow HTTP request smugggling. A c...Show more |
2Debian Libreoffice2Debian Linux LibreofficeJun 17, 2026 Oct 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper...Show more |
2Debian Tinyxml Project2Debian Linux TinyxmlJun 17, 2026 Oct 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service. |
2Debian Libreoffice2Debian Linux LibreofficeJun 17, 2026 Oct 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 8, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |