Vulnerabilities > Debian > Debian Linux

DATE CVE VULNERABILITY TITLE RISK
2021-09-16 CVE-2020-21531 Classic Buffer Overflow vulnerability in multiple products
fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.
local
low complexity
xfig-project debian CWE-120
5.5
2021-09-16 CVE-2020-21532 Classic Buffer Overflow vulnerability in multiple products
fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
local
low complexity
xfig-project debian CWE-120
5.5
2021-09-16 CVE-2020-21533 Out-of-bounds Write vulnerability in multiple products
fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.
local
low complexity
xfig-project debian CWE-787
5.5
2021-09-16 CVE-2020-21534 Classic Buffer Overflow vulnerability in multiple products
fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.
local
low complexity
xfig-project debian CWE-120
5.5
2021-09-16 CVE-2020-21535 Out-of-bounds Read vulnerability in multiple products
fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.
local
low complexity
xfig-project debian CWE-125
5.5
2021-09-16 CVE-2021-34798 NULL Pointer Dereference vulnerability in multiple products
Malformed requests may cause the server to dereference a NULL pointer.
7.5
2021-09-16 CVE-2021-36160 Out-of-bounds Read vulnerability in multiple products
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS).
7.5
2021-09-16 CVE-2021-39275 Out-of-bounds Write vulnerability in multiple products
ap_escape_quotes() may write beyond the end of a buffer when given malicious input.
network
low complexity
apache fedoraproject debian netapp oracle siemens CWE-787
critical
9.8
2021-09-16 CVE-2021-40438 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
9.0
2021-09-16 CVE-2021-41079 Infinite Loop vulnerability in multiple products
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets.
network
low complexity
apache debian netapp CWE-835
7.5