Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectOracle6Debian Linux FedoraGraalvm+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 3.1 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterpris...Show more |
2Artifex Debian2Debian Linux MupdfJun 17, 2026 Jul 21, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service. |
4Debian FedoraprojectNetapp+1 more5Debian Linux FedoraHci Management Node+2 moreJun 17, 2026 Jul 20, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an o...Show more |
6Debian FedoraprojectLinux+3 more7Communications Session Border Controller Debian LinuxFedora+4 moreJun 17, 2026 Jul 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged use...Show more |
3Debian FedoraprojectLibsndfile Project3Debian Linux FedoraLibsndfileJun 17, 2026 Jul 20, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file. |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Jul 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file |
3Debian FedoraprojectGnu3Aspell Debian LinuxFedoraJun 17, 2026 Jul 20, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list). |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte). |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by chang...Show more |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values. |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator. |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbe...Show more |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed. |
4Debian ScirubyUblockorigin+1 more4Debian Linux NmatrixUblock Origin+1 moreJun 17, 2026 Jul 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger...Show more |
2Debian Icinga2Debian Linux IcingaJun 17, 2026 Jul 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through vers...Show more |
2Debian Icinga2Debian Linux IcingaJun 17, 2026 Jul 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists...Show more |
5Debian FedoraprojectVarnish Cache+2 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x...Show more |
3Arm DebianFedoraproject3Debian Linux FedoraMbed TlsJun 17, 2026 Jul 14, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-ch...Show more |
2Debian Exiv22Debian Linux Exiv2Jun 17, 2026 Jul 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS). |
3Debian FedoraprojectPython3Debian Linux FedoraPillowJun 17, 2026 Jul 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c. |