Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow...Show more |
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow...Show more |
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow...Show more |
3Debian FedoraprojectHaproxy3Debian Linux FedoraHaproxyJun 17, 2026 Aug 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mis...Show more |
3Debian FedoraprojectHaproxy3Debian Linux FedoraHaproxyJun 17, 2026 Aug 17, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that...Show more |
3Debian FedoraprojectHaproxy3Debian Linux FedoraHaproxyJun 17, 2026 Aug 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field...Show more |
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 i...Show more |
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory alloca...Show more |
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The stri_box_read function is used when processing atoms using the '...Show more |
5Debian NetappNodejs+2 more7Debian Linux GraalvmJd Edwards Enterpriseone Tools+4 moreJun 17, 2026 Aug 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. |
5Debian NetappNodejs+2 more8Debian Linux GraalvmJd Edwards Enterpriseone Tools+5 moreJun 17, 2026 Aug 16, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted. |
5Apache DebianFedoraproject+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Aug 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. |
4Ckeditor DebianFedoraproject+1 more12Application Express Banking Party ManagementCkeditor+9 moreJun 17, 2026 Aug 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability...Show more |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Aug 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Aug 10, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file. |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Aug 10, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code. |
2Debian Fig2dev Project2Debian Linux Fig2devJun 17, 2026 Aug 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format. |
2Debian Fig2dev Project2Debian Linux Fig2devJun 17, 2026 Aug 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format. |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Aug 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered...Show more |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Aug 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered...Show more |