VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2012-0879MedMay 17, 2012
    risk 0.29cvss 5.5epss 0.00

    The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.

  • CVE-2026-57214MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a…

  • CVE-2023-27539MedJan 9, 2025
    risk 0.28cvss 5.3epss 0.01

    There is a denial of service vulnerability in the header parsing component of Rack.

  • CVE-2024-8508MedOct 3, 2024
    risk 0.28cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying…

  • CVE-2024-5690MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.01

    By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

  • CVE-2024-4767MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

  • CVE-2024-29025MedMar 25, 2024
    risk 0.28cvss 5.3epss 0.01

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so,…

  • CVE-2024-26146MedFeb 29, 2024
    risk 0.28cvss 5.3epss 0.02

    Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack…

  • CVE-2024-27285MedFeb 28, 2024
    risk 0.28cvss 5.4epss 0.01

    YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This…

  • CVE-2024-1548MedFeb 20, 2024
    risk 0.28cvss 4.3epss 0.01

    A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

  • CVE-2024-0749MedJan 23, 2024
    risk 0.28cvss 4.3epss 0.00

    A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.

  • CVE-2024-0742MedJan 23, 2024
    risk 0.28cvss 4.3epss 0.01

    It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

  • CVE-2024-22049MedJan 4, 2024
    risk 0.28cvss 5.3epss 0.01

    httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

  • CVE-2023-50762MedDec 19, 2023
    risk 0.28cvss 4.3epss 0.01

    When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text was interpreted as a MIME message and the first paragraph was always treated as an email header section. A digitally…

  • CVE-2023-50761MedDec 19, 2023
    risk 0.28cvss 4.3epss 0.01

    The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despite a date or time…

  • CVE-2023-6511MedDec 6, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5859MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)

  • CVE-2023-5858MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5853MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-5851MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-5850MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

  • CVE-2023-5725MedOct 25, 2023
    risk 0.28cvss 4.3epss 0.01

    A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-5721MedOct 25, 2023
    risk 0.28cvss 4.3epss 0.01

    It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-5486MedOct 11, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5485MedOct 11, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5478MedOct 11, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5477MedOct 11, 2023
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)

  • CVE-2023-45648MedOct 10, 2023
    risk 0.28cvss 5.3epss 0.06

    Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer…

  • CVE-2023-42795MedOct 10, 2023
    risk 0.28cvss 5.3epss 0.02

    Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some…

  • CVE-2023-4909MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4908MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4907MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4906MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4905MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4904MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)

  • CVE-2023-4903MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4902MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4901MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4900MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4365MedAug 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4364MedAug 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4363MedAug 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4360MedAug 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-36351MedAug 11, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2023-2468MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-2467MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-2466MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-2465MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-2464MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-2463MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

Page 149 of 210