VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Debian
> Debian Linux
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2022-09-26
CVE-2022-21797
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
network
low complexity
joblib-project
fedoraproject
debian
critical
9.8
9.8
2022-09-23
CVE-2022-40188
Algorithmic Complexity vulnerability in multiple products
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity.
network
low complexity
nic
fedoraproject
debian
CWE-407
7.5
7.5
2022-09-23
CVE-2022-35252
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses.
network
high complexity
haxx
netapp
apple
debian
splunk
3.7
3.7
2022-09-22
CVE-2022-1941
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures.
network
low complexity
google
fedoraproject
debian
7.5
7.5
2022-09-22
CVE-2022-38398
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol.
network
low complexity
apache
debian
5.3
5.3
2022-09-22
CVE-2022-38648
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources.
network
low complexity
apache
debian
5.3
5.3
2022-09-22
CVE-2022-40146
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url.
network
low complexity
apache
debian
7.5
7.5
2022-09-22
CVE-2022-3256
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
local
low complexity
vim
fedoraproject
debian
7.8
7.8
2022-09-21
CVE-2022-2795
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
network
low complexity
isc
debian
fedoraproject
5.3
5.3
2022-09-21
CVE-2022-38177
Memory Leak vulnerability in multiple products
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak.
network
low complexity
isc
debian
fedoraproject
netapp
CWE-401
7.5
7.5
«
Previous
1
2
...
72
73
74
(current)
75
76
...
753
754
»
Next