Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server...Show more |
3Debian FedoraprojectGetcomposer3Composer Debian LinuxFedoraJun 17, 2026 Apr 27, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot b...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation ca...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbou...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely o...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a runnin...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installatio...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation ca...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of...Show more |
3Debian Exiv2Fedoraproject3Debian Linux Exiv2FedoraJun 17, 2026 Apr 26, 2021 N/A· v4 2.5 LOW· v3 2.6 LOW· v2 Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line u...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. |