Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectQemu+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 18, 2021 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A...Show more |
4Debian FedoraprojectLinux+1 more12Cloud Backup Debian LinuxFedora+9 moreJun 17, 2026 Mar 17, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not...Show more |
3Debian FedoraprojectPygments3Debian Linux FedoraPygmentsJun 17, 2026 Mar 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to...Show more |
2Apache Debian2Debian Linux SubversionJun 17, 2026 Mar 17, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead...Show more |
The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less users even if they are connected by non-phy...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian OracleWireshark3Debian Linux WiresharkZfs Storage ApplianceJun 17, 2026 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file. |
1Debian 2Courier Authlib Debian LinuxJun 17, 2026 Mar 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a c...Show more |
2Debian Xmldom Project2Debian Linux XmldomJun 17, 2026 Mar 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly p...Show more |
3Debian FedoraprojectLeptonica3Debian Linux FedoraLeptonicaJun 17, 2026 Mar 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. |
3Debian FedoraprojectLeptonica3Debian Linux FedoraLeptonicaJun 17, 2026 Mar 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c. |
3Debian FedoraprojectLeptonica3Debian Linux FedoraLeptonicaJun 17, 2026 Mar 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. |
4Broadcom DebianFedoraproject+1 more4Brocade Fabric Operating System Firmware Debian LinuxFedora+1 moreJun 17, 2026 Mar 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlin...Show more |
3Debian FedoraprojectLeptonica3Debian Linux FedoraLeptonicaJun 17, 2026 Mar 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c. |
3Debian FedoraprojectFlatpak3Debian Linux FedoraFlatpakJun 17, 2026 Mar 11, 2021 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which ca...Show more |
2Debian Teluu2Debian Linux PjsipJun 17, 2026 Mar 10, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial...Show more |
33mf DebianFedoraproject3Debian Linux FedoraLib3mfJun 17, 2026 Mar 10, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious...Show more |
2Apache Debian2Debian Linux Velocity ToolsJun 17, 2026 Mar 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which result...Show more |