Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraJson C+2 moreJun 17, 2026 May 9, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. |
6Canonical DebianLinux+3 more22Active Iq Unified Manager Debian LinuxElement Software+19 moreJun 17, 2026 May 8, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /d...Show more |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a...Show more |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 3.3 LOW· v3 4.9 MEDIUM· v2 In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This...Show more |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 May 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 May 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overf...Show more |
3Debian GraphicsmagickOpensuse4Backports Sle Debian LinuxGraphicsmagick+1 moreJun 17, 2026 May 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. |
4Debian LinuxNetapp+1 more22A700s Firmware Active Iq Unified ManagerCloud Backup+19 moreJun 17, 2026 May 5, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an...Show more |
3Debian FedoraprojectRuby Lang3Debian Linux FedoraRubyJun 17, 2026 May 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the request...Show more |
2Debian Roundcube2Debian Linux WebmailJun 17, 2026 May 4, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered. |
3Debian OpensuseRoundcube4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 May 4, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add conte...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful exec...Show more |