VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Debian
> Medium
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2021-11-12
CVE-2021-43332
Insufficiently Protected Credentials vulnerability in multiple products
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password.
network
low complexity
gnu
debian
CWE-522
6.5
6.5
2021-11-11
CVE-2021-3911
Unchecked Return Value vulnerability in multiple products
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
network
low complexity
cloudflare
debian
CWE-252
6.5
6.5
2021-11-11
CVE-2021-3912
Allocation of Resources Without Limits or Throttling vulnerability in multiple products
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
network
low complexity
cloudflare
debian
CWE-770
6.5
6.5
2021-11-04
CVE-2021-43389
Out-of-bounds Read vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.14.15.
local
low complexity
linux
redhat
debian
oracle
CWE-125
5.5
5.5
2021-11-03
CVE-2021-22960
HTTP Request Smuggling vulnerability in multiple products
The parse function in llhttp < 2.1.4 and < 6.0.6.
network
low complexity
llhttp
oracle
debian
CWE-444
6.5
6.5
2021-11-03
CVE-2021-40985
Out-of-bounds Read vulnerability in multiple products
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
local
low complexity
htmldoc-project
debian
CWE-125
5.5
5.5
2021-11-03
CVE-2021-38502
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection.
network
high complexity
mozilla
debian
5.9
5.9
2021-11-02
CVE-2021-37989
Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.
network
low complexity
google
debian
6.5
6.5
2021-11-02
CVE-2021-37990
Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.
local
low complexity
google
debian
5.5
5.5
2021-11-02
CVE-2021-37994
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google
debian
6.5
6.5
«
Previous
1
2
...
64
65
66
(current)
67
68
...
304
305
»
Next