Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OracleRuby Lang3Debian Linux Jd Edwards Enterpriseone ToolsRubyJun 17, 2026 Jul 13, 2021 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This pote...Show more |
4Apache DebianMcafee+1 more22Agile Plm Communications Cloud Native Core PolicyCommunications Cloud Native Core Service Communication Proxy+19 moreJun 17, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used...Show more |
3Apache DebianOracle7Communications Cloud Native Core Policy Communications Diameter Signaling RouterCommunications Pricing Design Center+4 moreJun 17, 2026 Jul 12, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache...Show more |
6Debian FedoraprojectLinux+3 more17Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+14 moreJun 17, 2026 Jul 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or...Show more |
4Debian FedoraprojectLinuxptp Project+1 more7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreJun 17, 2026 Jul 9, 2021 N/A· v4 8.8 HIGH· v3 8.0 HIGH· v2 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code e...Show more |
3Debian FedoraprojectWebkitgtk3Debian Linux FedoraWebkitgtkJun 17, 2026 Jul 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A...Show more |
3Debian FedoraprojectWebkitgtk3Debian Linux FedoraWebkitgtkJun 17, 2026 Jul 7, 2021 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory c...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jul 7, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not oc...Show more |
3Debian OpenexrRedhat3Debian Linux Enterprise LinuxOpenexrJun 17, 2026 Jul 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Jul 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages th...Show more |
4Debian FedoraprojectNetapp+1 more8Active Iq Unified Manager Bootstrap OsDebian Linux+5 moreJun 17, 2026 Jul 1, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list). |
3Debian Djvulibre ProjectFedoraproject3Debian Linux DjvulibreFedoraJun 17, 2026 Jun 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jun 28, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address. |
2Debian Djvulibre Project2Debian Linux DjvulibreJun 17, 2026 Jun 24, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences. |
2Debian Djvulibre Project2Debian Linux DjvulibreJun 17, 2026 Jun 24, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences. |