Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Aug 2, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibi...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Aug 2, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not...Show more |
2Debian Lemonldap Ng2Debian Linux Lemonldap\Jun 17, 2026 Jul 30, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be a...Show more |
3Debian FedoraprojectPhp3Archive Tar Debian LinuxFedoraJun 17, 2026 Jul 30, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193. |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Jul 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet th...Show more |
3Debian OracleRuby Lang3Debian Linux Jd Edwards Enterpriseone ToolsRdocJun 17, 2026 Jul 30, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename. |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Jul 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. |
2Debian Teluu2Debian Linux PjsipJun 17, 2026 Jul 23, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple...Show more |
3Debian NetappOpenidc3Cloud Backup Debian LinuxMod Auth OpenidcJun 17, 2026 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc...Show more |
4Debian MitNetapp+1 more7Active Iq Unified Manager Debian LinuxKerberos 5+4 moreJun 17, 2026 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. Thi...Show more |
3Debian GnuNetapp7Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+4 moreJun 17, 2026 Jul 22, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial...Show more |
3Debian FedoraprojectOisf3Debian Linux FedoraSuricataJun 17, 2026 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion." |
2Debian Nvidia2Debian Linux Gpu Display DriverJun 17, 2026 Jul 22, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead t...Show more |
2Debian Nvidia2Debian Linux Gpu Display DriverJun 17, 2026 Jul 22, 2021 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information...Show more |
2Debian Nvidia2Debian Linux Gpu Display DriverJun 17, 2026 Jul 22, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or...Show more |
3Debian FedoraprojectRedislabs3Debian Linux FedoraRedisJun 17, 2026 Jul 21, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5....Show more |
3Debian LinuxOracle5Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+2 moreJun 17, 2026 Jul 21, 2021 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free. |
2Debian Oracle5Debian Linux GraalvmJdk+2 moreJun 17, 2026 Jul 21, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition:...Show more |
2Debian Oracle5Debian Linux GraalvmJdk+2 moreJun 17, 2026 Jul 21, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise E...Show more |