Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGnome3Debian Linux FedoraGdkpixbufJun 17, 2026 Jan 12, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12. |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength of deblock.cc has occurred. The vulnerability causes a segmentation fa...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265. |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Jan 10, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted...Show more |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265. |
2Debian Struktur2Debian Linux Libde265Jun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc. |
3Debian FedoraprojectSmarty3Debian Linux FedoraSmartyJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a maliciou...Show more |
3Debian FedoraprojectSmarty3Debian Linux FedoraSmartyJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users shou...Show more |
3Debian LibtiffNetapp3Debian Linux LibtiffOntap Select Deploy Administration UtilityJun 17, 2026 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. |
2Debian Htmldoc Project2Debian Linux HtmldocJun 17, 2026 Jan 10, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file. |
3Debian H2databaseOracle3Communications Cloud Native Core Policy Debian LinuxH2Jun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI serve...Show more |