← Back

Debian Linux

debian_linux

Vendor: Debian • 10,001 CVEs

CVEs (10,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Jan 11, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Jan 11, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size fun...Show more
In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).Show less
4Debian
FasterxmlNetapp+1 more
8Debian Linux
E Series Santricity Os ControllerE Series Santricity Web Services Proxy+5 more
Aug 27, 2025
Jan 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending malic...Show more
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.Show less
2Debian
Redmine
2Debian Linux
Redmine
Nov 21, 2024
Jan 10, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Merc...Show more
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.Show less
2Debian
Mono Project
2Debian Linux
Mono
Nov 21, 2024
Jan 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
2Debian
Mono Project
2Debian Linux
Mono
Nov 21, 2024
Jan 8, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" iss...Show more
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.Show less
2Debian
Libming
2Debian Linux
Libming
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafte...Show more
In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.Show less
2Debian
Opencv
2Debian Linux
Opencv
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
2Debian
Opencv
2Debian Linux
Opencv
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
2Debian
Irssi
2Debian Linux
Irssi
Nov 21, 2024
Jan 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.
2Debian
Irssi
2Debian Linux
Irssi
Nov 21, 2024
Jan 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
2Debian
Irssi
2Debian Linux
Irssi
Nov 21, 2024
Jan 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
3Canonical
DebianIrssi
3Debian Linux
IrssiUbuntu Linux
Nov 21, 2024
Jan 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
2Debian
Libming
2Debian Linux
Libming
Nov 21, 2024
Jan 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service...Show more
In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted swf file.Show less
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
Nov 21, 2024
Jan 5, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode function.
2Debian
Ibm
2Debian Linux
Security Key Lifecycle Manager
Nov 21, 2024
Jan 4, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
13Arm
CanonicalDebian+10 more
308Atom C
Atom EAtom X3+305 more
May 28, 2026
Jan 4, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
7Arm
CanonicalDebian+4 more
220Atom C
Atom EAtom X3+217 more
May 6, 2025
Jan 4, 2018
N/A· v4
5.6 MEDIUM· v3
1.9 LOW· v2
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
2Codehaus Plexus
Debian
2Debian Linux
Plexus Utils
Nov 21, 2024
Jan 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
2Debian
Pocoproject
2Debian Linux
Poco
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal a...Show more
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".Show less