Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS. |
2Contribsys Debian2Debian Linux SidekiqJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used. |
2Debian Htmldoc Project2Debian Linux HtmldocJun 17, 2026 Apr 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181. |
3Debian FedoraprojectLibpano13 Project3Debian Linux FedoraLibpano13Jun 17, 2026 Apr 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values. |
5Debian FedoraprojectNetapp+2 more6Active Iq Unified Manager Debian LinuxEnterprise Linux+3 moreJun 17, 2026 Apr 5, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called wi...Show more |
3Apple DebianFedoraproject6Debian Linux FedoraIpados+3 moreJun 17, 2026 Apr 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be ab...Show more |
3Apple DebianFedoraproject8Debian Linux FedoraIpados+5 moreJun 17, 2026 Apr 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing m...Show more |
3Apple DebianFedoraproject9Debian Linux FedoraIpados+6 moreJun 17, 2026 Apr 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iP...Show more |
2Apple Debian2Debian Linux Mac Os XJun 17, 2026 Apr 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 2, 2021 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b. |
8Broadcom DebianFedoraproject+5 more11Communications Billing And Revenue Management Debian LinuxEssbase+8 moreJun 17, 2026 Apr 1, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confus...Show more |
8Broadcom DebianFedoraproject+5 more12Communications Billing And Revenue Management Debian LinuxEssbase+9 moreJun 17, 2026 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials f...Show more |
2Debian Openexr2Debian Linux OpenexrJun 17, 2026 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer de...Show more |
2Debian Openexr2Debian Linux OpenexrJun 17, 2026 Mar 31, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting i...Show more |
2Debian Openexr2Debian Linux OpenexrJun 17, 2026 Mar 31, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact...Show more |