Vulnerabilities > Debian > Debian Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-04-06 CVE-2021-30158 Improper Authentication vulnerability in multiple products
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2.
network
low complexity
mediawiki debian fedoraproject CWE-287
5.3
2021-04-06 CVE-2021-30157 Cross-site Scripting vulnerability in multiple products
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2.
network
low complexity
mediawiki debian fedoraproject CWE-79
6.1
2021-04-06 CVE-2021-30154 Cross-site Scripting vulnerability in multiple products
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2.
network
low complexity
mediawiki debian fedoraproject CWE-79
6.1
2021-04-06 CVE-2021-30151 Cross-site Scripting vulnerability in multiple products
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
network
low complexity
contribsys debian CWE-79
6.1
2021-04-02 CVE-2020-10001 Improper Input Validation vulnerability in multiple products
An input validation issue was addressed with improved memory handling.
local
low complexity
apple debian CWE-20
5.5
2021-04-02 CVE-2021-30002 Memory Leak vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists.
local
low complexity
linux debian CWE-401
6.2
2021-04-01 CVE-2021-22876 Information Exposure vulnerability in multiple products
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header.
5.3
2021-04-01 CVE-2021-20296 A flaw was found in OpenEXR in versions before 3.0.0-beta.
network
low complexity
openexr debian
5.3
2021-03-31 CVE-2021-3479 There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta.
local
low complexity
openexr debian
5.5
2021-03-31 CVE-2021-3478 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta.
local
low complexity
openexr debian
5.5