VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2023-2133HigApr 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1820HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-1818HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-1815HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-1812HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-1811HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1810HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-23125CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not…

  • CVE-2022-23124CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.03

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper…

  • CVE-2022-23123CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper…

  • CVE-2022-23122CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper…

  • CVE-2022-23121CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.09

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error…

  • CVE-2022-0194CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper…

  • CVE-2023-26314HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.01

    The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.

  • CVE-2022-46871HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

  • CVE-2022-46344HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.03

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on…

  • CVE-2022-46343HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and…

  • CVE-2022-46342HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se

  • CVE-2022-46341HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.03

    A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is…

  • CVE-2022-46340HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can…

  • CVE-2022-3889HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3888HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3887HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3886HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3885HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-44638HigNov 3, 2022
    risk 0.57cvss 8.8epss 0.01

    In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.

  • CVE-2022-42823HigNov 1, 2022
    risk 0.57cvss 8.8epss 0.01

    A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-42309HigNov 1, 2022
    risk 0.57cvss 8.8epss 0.00

    Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the…

  • CVE-2022-37454CriOct 21, 2022
    risk 0.57cvss 9.8epss 0.05

    The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

  • CVE-2022-42902HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

  • CVE-2022-37601CriOct 12, 2022
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

  • CVE-2022-37616CriOct 11, 2022
    risk 0.57cvss 9.8epss 0.02

    A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third…

  • CVE-2022-32886HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-33745HigJul 26, 2022
    risk 0.57cvss 8.8epss 0.00

    insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable…

  • CVE-2022-26307HigJul 25, 2022
    risk 0.57cvss 8.8epss 0.01

    LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening…

  • CVE-2022-30550HigJul 17, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly…

  • CVE-2019-9972HigJun 7, 2022
    risk 0.57cvss 8.8epss 0.02

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of " followed by " mishandling.

  • CVE-2019-9971HigJun 7, 2022
    risk 0.57cvss 8.8epss 0.02

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used…

  • CVE-2022-31799CriJun 2, 2022
    risk 0.57cvss 9.8epss 0.02

    Bottle before 0.12.20 mishandles errors during early request binding.

  • CVE-2022-21831CriMay 26, 2022
    risk 0.57cvss 9.8epss 0.03

    A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

  • CVE-2022-29599CriMay 23, 2022
    risk 0.57cvss 9.8epss 0.04

    In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

  • CVE-2022-29501HigMay 5, 2022
    risk 0.57cvss 8.8epss 0.03

    SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.

  • CVE-2022-29500HigMay 5, 2022
    risk 0.57cvss 8.8epss 0.02

    SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.

  • CVE-2020-35632HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-35631HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-35630HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-35629HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-28635HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-28634HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

  • CVE-2020-28633HigApr 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious…

Page 22 of 210