Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Xfig Project2Debian Linux Fig2devJun 17, 2026 Sep 16, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c. |
2Debian Xfig Project2Debian Linux Fig2devJun 17, 2026 Sep 16, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. |
3Apache DebianNetapp3Debian Linux Management Services For Element Software And Netapp HciTomcatJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet...Show more |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreAug 1, 2026 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
6Apache DebianFedoraproject+3 more11Cloud Backup Clustered Data OntapDebian Linux+8 moreJun 17, 2026 Sep 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Serve...Show more |
6Apache BroadcomDebian+3 more13Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+10 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). |
8Apache BroadcomDebian+5 more18Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+15 moreJun 17, 2026 Sep 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. |
4Debian FedoraprojectNetapp+1 more4Debian Linux FedoraOntap Select Deploy Administration Utility+1 moreJun 17, 2026 Sep 15, 2021 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Use After Free |
4Debian FedoraprojectNetapp+1 more4Debian Linux FedoraOntap Select Deploy Administration Utility+1 moreJun 17, 2026 Sep 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
2Debian Squashfs Tools Project2Debian Linux Squashfs ToolsJun 17, 2026 Sep 14, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents u...Show more |
2Atftp Project Debian2Atftp Debian LinuxJun 17, 2026 Sep 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 9, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 9, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions,...Show more |
3Debian NetappSimplesystems3Debian Linux LibtiffOntap Select Deploy Administration UtilityJun 17, 2026 Sep 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'. |
2Debian Simplesystems2Debian Linux LibtiffJun 17, 2026 Sep 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Sep 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim networ...Show more |
3Debian FedoraprojectHaproxy3Debian Linux FedoraHaproxyJun 17, 2026 Sep 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possi...Show more |
3Debian FedoraprojectRibbonsoft4Debian Linux DxflibExtra Packages For Enterprise Linux+1 moreJun 17, 2026 Sep 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious f...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Sep 8, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Sep 8, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant tabl...Show more |