VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2021-39258HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.

  • CVE-2021-39256HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.

  • CVE-2021-39255HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.

  • CVE-2021-39254HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.

  • CVE-2021-39253HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.

  • CVE-2021-39252HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

  • CVE-2021-39251HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

  • CVE-2021-33286HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.

  • CVE-2021-33285HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which…

  • CVE-2021-39847HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.05

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

  • CVE-2021-36064HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.03

    XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2021-36055HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.03

    XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2021-36052HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.03

    XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

  • CVE-2021-36050HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.05

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

  • CVE-2021-36048HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.03

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

  • CVE-2021-36047HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.03

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

  • CVE-2021-36046HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.02

    XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

  • CVE-2021-28697HigAug 27, 2021
    risk 0.51cvss 7.8epss 0.00

    grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get…

  • CVE-2021-30954HigAug 24, 2021
    risk 0.51cvss 7.8epss 0.01

    A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-38166HigAug 7, 2021
    risk 0.51cvss 7.8epss 0.00

    In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

  • CVE-2021-32761HigJul 21, 2021
    risk 0.51cvss 7.5epss 0.31

    Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit systems, Redis `*BIT*` command are vulnerable to…

  • CVE-2021-3612HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The…

  • CVE-2021-3500HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences.

  • CVE-2021-32493HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences.

  • CVE-2021-32492HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences.

  • CVE-2021-32491HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.

  • CVE-2021-32490HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.

  • CVE-2021-22543HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random…

  • CVE-2020-25671HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.

  • CVE-2020-25670HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.

  • CVE-2021-3483HigMay 17, 2021
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as…

  • CVE-2021-33034HigMay 14, 2021
    risk 0.51cvss 7.8epss 0.01

    In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

  • CVE-2020-27823HigMay 13, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • CVE-2021-23134HigMay 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

  • CVE-2020-18032HigApr 29, 2021
    risk 0.51cvss 7.8epss 0.03

    Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.

  • CVE-2021-31523HigApr 21, 2021
    risk 0.51cvss 7.8epss 0.00

    The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency.

  • CVE-2021-3498HigApr 19, 2021
    risk 0.51cvss 7.8epss 0.02

    GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.

  • CVE-2021-3497HigApr 19, 2021
    risk 0.51cvss 7.8epss 0.01

    GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

  • CVE-2017-20002HigMar 17, 2021
    risk 0.51cvss 7.8epss 0.00

    The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less users even if they are connected by non-physical means such as SSH (hence bypassing PAM's…

  • CVE-2021-27365HigMar 7, 2021
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up…

  • CVE-2020-28243HigFeb 27, 2021
    risk 0.51cvss 7.8epss 0.04

    An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

  • CVE-2021-3410HigFeb 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.

  • CVE-2021-27379HigFeb 18, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS crash) or gain privileges. This occurs because a backport missed a flush, and thus IOMMU updates were…

  • CVE-2021-26720HigFeb 17, 2021
    risk 0.51cvss 7.8epss 0.00

    avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE:…

  • CVE-2020-27814HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.02

    A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

  • CVE-2020-14409HigJan 19, 2021
    risk 0.51cvss 7.8epss 0.01

    SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

  • CVE-2020-35459HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.

  • CVE-2020-26664HigJan 8, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

  • CVE-2020-27844HigJan 5, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality,…

  • CVE-2020-26259MedDec 16, 2020
    risk 0.51cvss 6.8epss 0.82

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know files on the host as…

Page 52 of 210