Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Openstack2Debian Linux HorizonJun 17, 2026 Dec 4, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply...Show more |
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address. |
4Apache DebianNetapp+1 more12Blockchain Platform Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Policy+9 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 c...Show more |
6Debian FedoraprojectLxml+3 more8Communications Offline Mediation Controller Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Dec 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could...Show more |
3Debian FreedesktopRedhat3Debian Linux Enterprise LinuxPopplerJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 3, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is p...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 3, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likel...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 3, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char`. T...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 3, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was p...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 3, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to appli...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 3, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some cases caused a value outside the range of type `int` to be returned. The flaw could be triggered by a cr...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Dec 3, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The...Show more |
4Debian HibernateOracle+1 more5Communications Cloud Native Core Console Debian LinuxHibernate Orm+2 moreJun 17, 2026 Dec 2, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments...Show more |
2Debian Gorillatoolkit2Debian Linux WebsocketJun 17, 2026 Dec 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket c...Show more |
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest m...Show more |
3Debian LinuxStarwindsoftware6Command Center Debian LinuxLinux Kernel+3 moreJun 17, 2026 Dec 2, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service. |
4Debian LinuxRedhat+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreJun 17, 2026 Dec 2, 2020 N/A· v4 4.1 MEDIUM· v3 1.9 LOW· v2 A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The hi...Show more |
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Dec 1, 2020 N/A· v4 5.2 MEDIUM· v3 3.6 LOW· v2 containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network contai...Show more |
2Debian Genivi2Debian Linux Diagnostic Log And TraceJun 17, 2026 Nov 30, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of char...Show more |
2Debian Readymedia Project2Debian Linux ReadymediaJun 17, 2026 Nov 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer o...Show more |