VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2022-24599MedFeb 24, 2022
    risk 0.42cvss 6.5epss 0.02

    In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it…

  • CVE-2021-3930MedFeb 18, 2022
    risk 0.42cvss 6.5epss 0.00

    An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a…

  • CVE-2022-21712HigFeb 7, 2022
    risk 0.42cvss 7.5epss 0.01

    twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent`…

  • CVE-2021-43859HigFeb 1, 2022
    risk 0.42cvss 7.5epss 0.08

    XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service…

  • CVE-2022-23837HigJan 21, 2022
    risk 0.42cvss 7.5epss 0.05

    In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

  • CVE-2021-35452MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.

  • CVE-2021-28715MedJan 6, 2022
    risk 0.42cvss 6.5epss 0.00

    Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are…

  • CVE-2021-28714MedJan 6, 2022
    risk 0.42cvss 6.5epss 0.00

    Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are…

  • CVE-2021-28713MedJan 5, 2022
    risk 0.42cvss 6.5epss 0.00

    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically…

  • CVE-2021-28712MedJan 5, 2022
    risk 0.42cvss 6.5epss 0.00

    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically…

  • CVE-2021-28711MedJan 5, 2022
    risk 0.42cvss 6.5epss 0.00

    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically…

  • CVE-2021-3842HigJan 4, 2022
    risk 0.42cvss 7.5epss 0.01

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-44716HigJan 1, 2022
    risk 0.42cvss 7.5epss 0.04

    net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

  • CVE-2021-41817HigJan 1, 2022
    risk 0.42cvss 7.5epss 0.03

    Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

  • CVE-2021-4068MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-4059MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-4054MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-38022MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-38021MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-38019MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-38018MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-38010MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

  • CVE-2021-38009MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-43545MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.02

    Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43542MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.02

    Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43541MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.02

    When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43536MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.02

    Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43528MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability…

  • CVE-2021-38507MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.01

    The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port…

  • CVE-2020-36135MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.01

    AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.

  • CVE-2019-8921MedNov 29, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting…

  • CVE-2021-22959MedNov 15, 2021
    risk 0.42cvss 6.5epss 0.03

    The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.

  • CVE-2021-43332MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.

  • CVE-2021-22960MedNov 3, 2021
    risk 0.42cvss 6.5epss 0.02

    The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

  • CVE-2021-37995MedNov 2, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-37994MedNov 2, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-37989MedNov 2, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.

  • CVE-2021-37137HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.07

    The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be…

  • CVE-2021-37136HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.06

    The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

  • CVE-2021-22946HigSep 29, 2021
    risk 0.42cvss 7.5epss 0.05

    A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed…

  • CVE-2021-3803HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.02

    nth-check is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3805HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.02

    object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2020-21599MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.

  • CVE-2020-21597MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.02

    libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

  • CVE-2020-21596MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.01

    libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file.

  • CVE-2021-41079HigSep 16, 2021
    risk 0.42cvss 7.5epss 0.07

    Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a…

  • CVE-2020-19144MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.02

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.

  • CVE-2020-19143MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.

  • CVE-2021-3761HigSep 9, 2021
    risk 0.42cvss 7.5epss 0.01

    Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a…

  • CVE-2021-40491MedSep 3, 2021
    risk 0.42cvss 6.5epss 0.01

    The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.

Page 93 of 210