Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Jun 21, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-mi...Show more |
3Alpine Project DebianFedoraproject3Alpine Debian LinuxFedoraJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letti...Show more |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. |
3Debian OpensuseRubyonrails3Debian Linux LeapRailsJun 17, 2026 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in...Show more |
3Canonical DebianRack Project3Debian Linux RackUbuntu LinuxJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix. |
3Debian OpensuseRubyonrails4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end use...Show more |
3Cisofy DebianFedoraproject3Debian Linux FedoraLynisJun 17, 2026 Jun 18, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data...Show more |
4Canonical CiscoDebian+1 more5Advanced Malware Protection For Endpoints Clam AntivirusDebian Linux+2 moreJun 17, 2026 Jun 18, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability...Show more |
6Canonical DebianFedoraproject+3 more6Bind Debian LinuxFedora+3 moreJun 17, 2026 Jun 17, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or mor...Show more |
4Canonical DebianLibvnc Project+1 more9Debian Linux LibvncserverSimatic Itc1500 Firmware+6 moreJun 17, 2026 Jun 17, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size. |