Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.1 CRITICAL· v3 7.5 HIGH· v2 In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.) |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a...Show more |
3Debian FedoraprojectW1.fi3Debian Linux FedoraWpa SupplicantJun 17, 2026 Feb 26, 2021 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of a...Show more |
4Debian GnuNetapp+1 more14500f Firmware A250 FirmwareCommunications Cloud Native Core Service Communication Proxy+11 moreJun 17, 2026 Feb 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input s...Show more |
5Apache DebianEclipse+2 more16Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services+13 moreJun 17, 2026 Feb 26, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may en...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more |
2Debian Mozilla2Debian Linux FirefoxJun 17, 2026 Feb 26, 2021 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability a...Show more |
3Aiohttp DebianFedoraproject3Aiohttp Debian LinuxFedoraJun 17, 2026 Feb 26, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could red...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agen...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive...Show more |
3Debian FedoraprojectQemu3Debian Linux FedoraQemuJun 17, 2026 Feb 25, 2021 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest...Show more |
4Apache DebianFedoraproject+1 more22Agile Engineering Data Management Banking ApisBanking Digital Experience+19 moreJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraGlibcJun 17, 2026 Feb 24, 2021 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service o...Show more |