Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Ezxml Project2Debian Linux EzxmlJun 17, 2026 Apr 15, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant. |
4Debian FedoraprojectLinuxfoundation+1 more4Ceph Ceph StorageDebian Linux+1 moreJun 17, 2026 Apr 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_...Show more |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 Apr 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1...Show more |
3Debian LinuxStarwindsoftware3Debian Linux Linux KernelStarwind Virtual SanJun 17, 2026 Apr 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: t...Show more |
4Apache DebianNetapp+1 more60Access Manager Active Iq Unified ManagerAgile Engineering Data Management+57 moreJun 17, 2026 Apr 13, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files...Show more |
2Debian Ezxml Project2Debian Linux EzxmlJun 17, 2026 Apr 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory handling, leading to a NULL pointer dereference while running strcmp()...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget(...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently hav...Show more |
4Debian Exiv2Fedoraproject+1 more4Debian Linux Enterprise LinuxExiv2+1 moreJun 17, 2026 Apr 8, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a cra...Show more |
4Debian FedoraprojectLinux+1 more13Cloud Backup Debian LinuxFedora+10 moreJun 17, 2026 Apr 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and ar...Show more |
2Clamav Debian2Clamav Debian LinuxJun 17, 2026 Apr 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 7, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many en...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 7, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 6, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite point...Show more |
2Debian Phpseclib2Debian Linux PhpseclibJun 17, 2026 Apr 6, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vu...Show more |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries. |