Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries c...Show more |
3Debian FedoraprojectThekelleys3Debian Linux DnsmasqFedoraJun 17, 2026 Jan 20, 2021 N/A· v4 8.1 HIGH· v3 8.3 HIGH· v2 A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can creat...Show more |
3Debian FedoraprojectThekelleys3Debian Linux DnsmasqFedoraJun 17, 2026 Jan 20, 2021 N/A· v4 8.1 HIGH· v3 8.3 HIGH· v2 A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as...Show more |
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of t...Show more |
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries....Show more |
3Debian FedoraprojectThekelleys3Debian Linux DnsmasqFedoraJun 17, 2026 Jan 20, 2021 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS...Show more |
3Debian FedoraprojectLibsdl3Debian Linux FedoraSimple Directmedia LayerJun 17, 2026 Jan 19, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file. |
4Debian FedoraprojectLibsdl+1 more4Debian Linux FedoraSimple Directmedia Layer+1 moreJun 17, 2026 Jan 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file. |
5Apache DebianFasterxml+2 more10Active Iq Unified Manager Commerce Experience ManagerCommerce Guided Search+7 moreJul 24, 2026 Jan 19, 2021 N/A· v4 8.1 HIGH· v3 8.3 HIGH· v2 A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as...Show more |
3Debian FedoraprojectMutt3Debian Linux FedoraMuttJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of e...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some partie...Show more |
5Debian FedoraprojectNetapp+2 more10Active Iq Unified Manager Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Offline Mediation Controller+7 moreJun 17, 2026 Jan 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demons...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Jan 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. |
2Bottlepy Debian2Bottle Debian LinuxJun 17, 2026 Jan 18, 2021 N/A· v4 6.8 MEDIUM· v3 5.8 MEDIUM· v2 The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a diff...Show more |
2Debian Flatpak2Debian Linux FlatpakJun 17, 2026 Jan 14, 2021 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on...Show more |
3Apache DebianOracle3Agile Plm Debian LinuxTomcatJun 17, 2026 Jan 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code discl...Show more |
4Apache DebianNetapp+1 more7Debian Linux Middleware Common Libraries And ToolsOncommand Unified Manager Core Package+4 moreJun 17, 2026 Jan 14, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBean...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Jan 14, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jan 13, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an X...Show more |
2Clusterlabs Debian2Crmsh Debian LinuxJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentiall...Show more |