Vulnerabilities > Debian

DATE CVE VULNERABILITY TITLE RISK
2021-12-15 CVE-2021-43113 Command Injection vulnerability in multiple products
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
network
low complexity
itextpdf debian CWE-77
critical
9.8
2021-12-14 CVE-2021-45046 It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.
network
high complexity
apache intel cvat siemens debian sonicwall fedoraproject
critical
9.0
2021-12-14 CVE-2021-44538 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow.
network
low complexity
matrix schildi cinny-project debian CWE-119
critical
9.8
2021-12-13 CVE-2021-43818 lxml is a library for processing XML and HTML in the Python language.
network
low complexity
lxml fedoraproject debian netapp oracle
7.1
2021-12-10 CVE-2021-44228 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. 10.0
2021-12-09 CVE-2021-43797 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients.
network
low complexity
netty quarkus netapp oracle debian
6.5
2021-12-08 CVE-2021-38503 Incorrect Authorization vulnerability in multiple products
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame.
network
low complexity
mozilla debian CWE-863
critical
10.0
2021-12-08 CVE-2021-38504 Use After Free vulnerability in multiple products
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash.
network
low complexity
mozilla debian CWE-416
8.8
2021-12-08 CVE-2021-38506 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user.
network
low complexity
mozilla debian CWE-1021
4.3
2021-12-08 CVE-2021-38507 Origin Validation Error vulnerability in multiple products
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80.
network
low complexity
mozilla debian CWE-346
6.5