Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Readymedia Project2Debian Linux ReadymediaJun 17, 2026 Nov 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer o...Show more |
2Debian Qemu2Debian Linux QemuJun 17, 2026 Nov 30, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver. |
3Debian LinuxNetapp8500f Firmware A250 FirmwareDebian Linux+5 moreJun 17, 2026 Nov 28, 2020 N/A· v4 3.6 LOW· v3 3.3 LOW· v2 An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantic...Show more |
5Apache DebianEclipse+2 more17Blockchain Platform Communications Converged Application Server Service ControllerCommunications Offline Mediation Controller+14 moreJun 17, 2026 Nov 28, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto...Show more |
2Debian Schedmd2Debian Linux SlurmJun 17, 2026 Nov 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem. |
3Debian Libvncserver ProjectRedhat3Debian Linux Enterprise LinuxLibvncserverJun 17, 2026 Nov 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exceptio...Show more |
2Debian Schedmd2Debian Linux SlurmJun 17, 2026 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin. |
3Debian FedoraprojectLibslirp Project3Debian Linux FedoraLibslirpJun 17, 2026 Nov 26, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. |
3Debian FedoraprojectLibslirp Project3Debian Linux FedoraLibslirpJun 17, 2026 Nov 26, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 6.3 MEDIUM· v3 5.4 MEDIUM· v2 A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly r...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local gu...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 6.4 MEDIUM· v3 3.3 LOW· v2 A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from othe...Show more |
3Debian FedoraprojectX11vnc Project3Debian Linux FedoraX11vncJun 17, 2026 Nov 25, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 25, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/...Show more |
3Debian HighlightjsOracle3Debian Linux Highlight.jsMysql Enterprise MonitorJun 17, 2026 Nov 24, 2020 N/A· v4 8.7 HIGH· v3 4.9 MEDIUM· v2 Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype p...Show more |
2Clusterlabs Debian2Debian Linux PacemakerJun 17, 2026 Nov 24, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be...Show more |
4Debian FedoraprojectMusl Libc+1 more4Debian Linux FedoraGraalvm+1 moreJun 17, 2026 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). |
2Debian Spip2Debian Linux SpipJun 17, 2026 Nov 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters. |
2Debian Postgresql2Debian Linux PostgresqlJun 17, 2026 Nov 23, 2020 N/A· v4 7.5 HIGH· v3 7.6 HIGH· v2 A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a...Show more |
3Debian MuttNeomutt3Debian Linux MuttNeomuttJun 17, 2026 Nov 23, 2020 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continu...Show more |