Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectIntel301Celeron 3855u Firmware Celeron 3865u FirmwareCeleron 3955u Firmware+298 moreJun 17, 2026 Nov 12, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. |
2Cacti Debian2Cacti Debian LinuxJun 17, 2026 Nov 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 10, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE:...Show more |
2Debian Moinmo2Debian Linux MoinmoinJun 17, 2026 Nov 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution. |
3Debian FedoraprojectLibrdf3Debian Linux FedoraRaptor Rdf Syntax LibraryNov 21, 2024 Nov 6, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen i...Show more |
2Debian Qemu2Debian Linux QemuJun 17, 2026 Nov 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol. |
2Debian Saltstack2Debian Linux SaltJun 17, 2026 Nov 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH. |
2Debian Saltstack2Debian Linux SaltJun 17, 2026 Nov 6, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Nov 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. |
4Asterisk DebianFedoraproject+1 more4Asterisk Certified AsteriskDebian Linux+1 moreJun 17, 2026 Nov 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVI...Show more |
3Debian FedoraprojectMaxmind3Debian Linux FedoraLibmaxminddbJun 17, 2026 Nov 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c. |
2Apache Debian2Debian Linux ShiroJun 17, 2026 Nov 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Nov 4, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper...Show more |
4Apple DebianFedoraproject+1 more5Debian Linux FedoraMac Os X+2 moreJun 17, 2026 Nov 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. |
4Debian FedoraprojectGoogle+1 more4Backports Sle ChromeDebian Linux+1 moreJun 17, 2026 Nov 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
3Debian GoogleOpensuse4Backports Sle ChromeDebian Linux+1 moreJun 17, 2026 Nov 3, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
6Cefsharp DebianFedoraproject+3 more8Backports Sle CefsharpChrome+5 moreJun 17, 2026 Nov 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 Nov 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet. |
3Debian GoogleOpensuse4Backports Sle ChromeDebian Linux+1 moreJun 17, 2026 Nov 3, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 Nov 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |