Vulnerabilities > Debian > Debian Linux > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-16 | CVE-2021-45088 | Cross-site Scripting vulnerability in multiple products XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. | 4.3 |
2021-12-15 | CVE-2021-0920 | Use After Free vulnerability in multiple products In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. | 6.4 |
2021-12-09 | CVE-2021-43797 | HTTP Request Smuggling vulnerability in multiple products Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. | 6.5 |
2021-12-08 | CVE-2021-38506 | Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. | 4.3 |
2021-12-08 | CVE-2021-38507 | Origin Validation Error vulnerability in multiple products The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. | 6.5 |
2021-12-08 | CVE-2021-38508 | Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. | 4.3 |
2021-12-08 | CVE-2021-38509 | Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. | 4.3 |
2021-12-08 | CVE-2021-43528 | Improper Privilege Management vulnerability in multiple products Thunderbird unexpectedly enabled JavaScript in the composition area. | 6.5 |
2021-12-08 | CVE-2021-43534 | Out-of-bounds Write vulnerability in multiple products Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. | 6.8 |
2021-12-08 | CVE-2021-43535 | Use After Free vulnerability in multiple products A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. | 6.8 |