Vulnerabilities > Debian > Debian Linux

DATE CVE VULNERABILITY TITLE RISK
2022-09-07 CVE-2022-40023 Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse.
network
low complexity
sqlalchemy debian
7.5
2022-09-06 CVE-2022-3134 Use After Free in GitHub repository vim/vim prior to 9.0.0389.
local
low complexity
vim debian
7.8
2022-09-06 CVE-2022-2735 A vulnerability was found in the PCS project.
local
low complexity
clusterlabs debian
7.8
2022-09-05 CVE-2022-38749 Out-of-bounds Write vulnerability in multiple products
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS).
network
low complexity
snakeyaml-project debian CWE-787
6.5
2022-09-05 CVE-2022-38750 Out-of-bounds Write vulnerability in multiple products
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS).
local
low complexity
snakeyaml-project debian CWE-787
5.5
2022-09-05 CVE-2022-38751 Out-of-bounds Write vulnerability in multiple products
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS).
network
low complexity
snakeyaml-project debian CWE-787
6.5
2022-09-05 CVE-2022-3008 Command Injection vulnerability in multiple products
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file.
network
low complexity
tinygltf-project debian CWE-77
8.8
2022-09-05 CVE-2022-39842 Integer Overflow or Wraparound vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.19.
local
low complexity
linux debian CWE-190
6.1
2022-09-03 CVE-2022-3099 Use After Free in GitHub repository vim/vim prior to 9.0.0360.
local
low complexity
vim fedoraproject debian
7.8
2022-09-02 CVE-2020-29260 Resource Exhaustion vulnerability in multiple products
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
network
low complexity
libvncserver-project debian CWE-400
7.5