Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jul 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. |
3Canonical DebianRack Project3Debian Linux RackUbuntu LinuxJun 17, 2026 Jul 2, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosu...Show more |
3Debian FedoraprojectLibraw3Debian Linux FedoraLibrawJun 17, 2026 Jul 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength)...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraGuacamoleJun 17, 2026 Jul 2, 2020 N/A· v4 6.7 MEDIUM· v3 6.2 MEDIUM· v2 Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs c...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraGuacamoleJun 17, 2026 Jul 2, 2020 N/A· v4 4.4 MEDIUM· v3 1.2 LOW· v2 Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in discl...Show more |
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c. |
2Debian Ntop2Debian Linux NdpiJun 17, 2026 Jul 1, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short. |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Jun 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770. |
3Debian OracleUclouvain3Debian Linux OpenjpegOutside In TechnologyJun 17, 2026 Jun 29, 2020 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be...Show more |
5Canonical Coturn ProjectDebian+2 more5Coturn Debian LinuxFedora+2 moreJun 17, 2026 Jun 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use t...Show more |
6Apache CanonicalDebian+3 more8Debian Linux LeapMysql Enterprise Monitor+5 moreJun 17, 2026 Jun 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such reques...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jun 25, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Jun 24, 2020 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached pub...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more |
3Canonical DebianGnu3Debian Linux MailmanUbuntu LinuxJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 2.6 LOW· v2 GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. |