Vulnerabilities > Debian > Debian Linux

DATE CVE VULNERABILITY TITLE RISK
2022-05-26 CVE-2022-30784 Classic Buffer Overflow vulnerability in multiple products
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
local
low complexity
tuxera debian fedoraproject CWE-120
7.8
2022-05-26 CVE-2022-30785 A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
local
low complexity
tuxera fedoraproject debian
6.7
2022-05-26 CVE-2022-30786 Out-of-bounds Write vulnerability in multiple products
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
local
low complexity
tuxera fedoraproject debian CWE-787
7.8
2022-05-26 CVE-2022-30787 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
local
low complexity
tuxera fedoraproject debian CWE-191
6.7
2022-05-26 CVE-2022-30788 Out-of-bounds Write vulnerability in multiple products
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
local
low complexity
tuxera fedoraproject debian CWE-787
7.8
2022-05-26 CVE-2022-30789 Out-of-bounds Write vulnerability in multiple products
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
local
low complexity
tuxera debian fedoraproject CWE-787
7.8
2022-05-26 CVE-2022-1664 Path Traversal vulnerability in multiple products
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability.
network
low complexity
debian netapp CWE-22
critical
9.8
2022-05-25 CVE-2022-29248 Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
Guzzle is a PHP HTTP client.
network
low complexity
guzzlephp drupal debian CWE-565
8.1
2022-05-25 CVE-2022-1851 Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
local
low complexity
vim fedoraproject debian apple
7.8
2022-05-24 CVE-2022-29221 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic.
network
low complexity
smarty debian fedoraproject
8.8