Vulnerabilities > Debian > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-30 CVE-2022-42259 Integer Overflow or Wraparound vulnerability in multiple products
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service.
local
low complexity
nvidia debian CWE-190
5.5
2022-12-22 CVE-2022-36354 A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0.
network
low complexity
openimageio debian
5.3
2022-12-22 CVE-2022-43592 An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
network
high complexity
openimageio debian
5.9
2022-12-22 CVE-2022-43593 A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
network
high complexity
openimageio debian
5.9
2022-12-22 CVE-2022-43594 NULL Pointer Dereference vulnerability in multiple products
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
network
high complexity
openimageio debian CWE-476
5.9
2022-12-22 CVE-2022-43595 Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
network
high complexity
openimageio debian
5.9
2022-12-22 CVE-2022-43596 An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
network
high complexity
openimageio debian
5.9
2022-12-22 CVE-2022-43603 A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
network
high complexity
openimageio debian
5.9
2022-12-22 CVE-2022-46877 By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks.
network
low complexity
mozilla debian
4.3
2022-12-14 CVE-2022-23520 Cross-site Scripting vulnerability in multiple products
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications.
network
low complexity
rubyonrails debian CWE-79
6.1