Vulnerabilities > Debian > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-17 CVE-2021-43976 In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). 4.6
2021-11-15 CVE-2021-22959 HTTP Request Smuggling vulnerability in multiple products
The parser in accepts requests with a space (SP) right after the header name before the colon.
network
low complexity
llhttp oracle debian CWE-444
6.5
2021-11-12 CVE-2021-41229 Memory Leak vulnerability in multiple products
BlueZ is a Bluetooth protocol stack for Linux.
low complexity
bluez debian CWE-401
6.5
2021-11-12 CVE-2021-43331 Cross-site Scripting vulnerability in multiple products
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.
network
low complexity
gnu debian CWE-79
6.1
2021-11-12 CVE-2021-43332 Insufficiently Protected Credentials vulnerability in multiple products
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password.
network
low complexity
gnu debian CWE-522
6.5
2021-11-11 CVE-2021-3908 Infinite Loop vulnerability in multiple products
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
network
low complexity
cloudflare debian CWE-835
5.0
2021-11-11 CVE-2021-3909 Resource Exhaustion vulnerability in multiple products
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever.
network
low complexity
cloudflare debian CWE-400
5.0
2021-11-11 CVE-2021-3910 Improper Input Validation vulnerability in multiple products
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
network
low complexity
cloudflare debian CWE-20
5.0
2021-11-11 CVE-2021-3911 Unchecked Return Value vulnerability in multiple products
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
4.3
2021-11-11 CVE-2021-3912 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
4.3