Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Redhat2Ansible Engine Debian LinuxJun 17, 2026 Sep 11, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of pe...Show more |
3Action View Project DebianFedoraproject3Action View Debian LinuxFedoraJun 17, 2026 Sep 11, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of...Show more |
3Debian FedoraprojectZeromq3Debian Linux FedoraLibzmqJun 17, 2026 Sep 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint...Show more |
2Debian Inspircd2Debian Linux InspircdJun 17, 2026 Sep 11, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remo...Show more |
2Debian Inspircd2Debian Linux InspircdJun 17, 2026 Sep 11, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqlope...Show more |
3Apache DebianOracle4Activemq Communications Diameter Signaling RouterDebian Linux+1 moreJun 17, 2026 Sep 10, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method...Show more |
3Atftp Project DebianOpensuse3Atftp Debian LinuxLeapJun 17, 2026 Sep 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denia...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack ex...Show more |
3Canonical DebianYaws3Debian Linux Ubuntu LinuxYawsJun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. |
3Canonical DebianYaws3Debian Linux Ubuntu LinuxYawsJun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. |
3Debian PhpTenable3Debian Linux PhpTenable.scJun 17, 2026 Sep 9, 2020 N/A· v4 3.6 LOW· v3 3.3 LOW· v2 In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Sep 9, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_fi...Show more |
5Canonical DebianFujitsu+2 more15Debian Linux Ethernet Switch Es1 24 FirmwareEthernet Switch Es2 64 Firmware+12 moreJun 17, 2026 Sep 9, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case...Show more |
3Arista DebianQualcomm13Access Point Apq8053 FirmwareDebian Linux+10 moreJun 17, 2026 Sep 8, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete s...Show more |
4Debian OpensuseOracle+1 more5Communications Cloud Native Core Network Function Cloud Native Environment Communications Cloud Native Core PolicyDebian Linux+2 moreJun 17, 2026 Sep 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/...Show more |
6Debian FedoraprojectNetapp+3 more18Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+15 moreJun 17, 2026 Sep 4, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. |
3Canonical DebianGruntjs3Debian Linux GruntUbuntu LinuxJun 17, 2026 Sep 3, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. |
5Canonical DebianFedoraproject+2 more5Ark Debian LinuxFedora+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |