Vulnerabilities > Debian

DATE CVE VULNERABILITY TITLE RISK
2022-02-11 CVE-2022-23772 Integer Overflow or Wraparound vulnerability in multiple products
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
network
low complexity
golang netapp debian CWE-190
7.5
2022-02-11 CVE-2022-23806 Unchecked Return Value vulnerability in multiple products
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
network
low complexity
golang netapp debian CWE-252
critical
9.1
2022-02-10 CVE-2022-0554 Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
local
low complexity
vim fedoraproject debian apple
7.8
2022-02-09 CVE-2022-0529 Out-of-bounds Write vulnerability in multiple products
A flaw was found in Unzip.
5.5
2022-02-09 CVE-2022-0530 A flaw was found in Unzip. 5.5
2022-02-09 CVE-2022-0534 Out-of-bounds Read vulnerability in multiple products
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).
local
low complexity
htmldoc-project debian CWE-125
5.5
2022-02-07 CVE-2022-21712 twisted is an event-driven networking engine written in Python.
network
low complexity
twisted debian fedoraproject
7.5
2022-02-05 CVE-2021-38172 Classic Buffer Overflow vulnerability in Debian Perm 0.4.0
perM 0.4.0 has a Buffer Overflow related to strncpy.
network
low complexity
debian CWE-120
critical
9.8
2022-02-04 CVE-2021-40401 Unchecked Return Value vulnerability in multiple products
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1.
local
low complexity
gerbv-project fedoraproject debian CWE-252
8.6
2022-02-04 CVE-2021-40403 An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0.
local
low complexity
gerbv-project fedoraproject debian
6.3