Vulnerabilities > Debian > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2022-27666 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c.
7.8
2022-03-22 CVE-2022-24764 PJSIP is a free and open source multimedia communication library written in C.
network
low complexity
teluu debian
7.5
2022-03-18 CVE-2022-1011 Use After Free vulnerability in multiple products
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write().
7.8
2022-03-17 CVE-2022-24761 HTTP Request Smuggling vulnerability in multiple products
Waitress is a Web Server Gateway Interface server for Python 2 and 3.
network
low complexity
agendaless debian CWE-444
7.5
2022-03-16 CVE-2021-20299 A flaw was found in OpenEXR's Multipart input file functionality.
network
low complexity
openexr debian
7.5
2022-03-16 CVE-2021-39713 Race Condition vulnerability in multiple products
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
local
high complexity
google debian CWE-362
7.0
2022-03-16 CVE-2022-26353 A flaw was found in the virtio-net device of QEMU.
network
low complexity
qemu debian
7.5
2022-03-16 CVE-2022-27223 Improper Validation of Array Index vulnerability in multiple products
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
network
low complexity
linux netapp debian CWE-129
8.8
2022-03-15 CVE-2022-0778 Infinite Loop vulnerability in multiple products
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli.
7.5
2022-03-14 CVE-2021-42387 Out-of-bounds Read vulnerability in multiple products
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query.
network
low complexity
yandex debian CWE-125
8.1