Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to uploa...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patc...Show more |
4Canonical DebianGnu+1 more8Active Iq Unified Manager Debian LinuxGlibc+5 moreJun 17, 2026 Apr 30, 2020 N/A· v4 7.0 HIGH· v3 3.7 LOW· v2 A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by...Show more |
6Blackberry CanonicalDebian+3 more6Application Remote Collector Debian LinuxLeap+3 moreJun 17, 2026 Apr 30, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary direc...Show more |
5Canonical DebianOpensuse+2 more5Application Remote Collector Debian LinuxLeap+2 moreJun 17, 2026 Apr 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without...Show more |
8Debian DrupalFedoraproject+5 more70Agile Product Lifecycle Management For Process Agile Product Supplier Collaboration For ProcessApplication Testing Suite+67 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted co...Show more |
7Debian DrupalFedoraproject+4 more52Active Iq Unified Manager Application ExpressApplication Testing Suite+49 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(),...Show more |
5Canonical DebianFedoraproject+2 more23A700s Firmware Active Iq Unified ManagerBootstrap Os+20 moreJun 17, 2026 Apr 29, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a...Show more |
5Apple DebianFedoraproject+2 more5Debian Linux FedoraJson+++2 moreJun 17, 2026 Apr 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on...Show more |
8Apple BroadcomCanonical+5 more18Brocade Fabric Operating System Cloud BackupDebian Linux+15 moreJun 17, 2026 Apr 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). |
2Debian Otrs2Debian Linux OtrsJun 17, 2026 Apr 28, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This iss...Show more |
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxJun 17, 2026 Apr 28, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Apr 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack. |
4Debian OraclePhp+1 more4Communications Diameter Signaling Router Debian LinuxPhp+1 moreJun 17, 2026 Apr 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erro...Show more |
2Debian Libgit22Debian Linux Libgit2Jun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository....Show more |
2Debian Libgit22Debian Linux Libgit2Jun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repos...Show more |
4Apache DebianOracle+1 more46Communications Application Session Controller Communications Billing And Revenue ManagementCommunications Eagle Ftp Table Base Retrieval+43 moreJun 17, 2026 Apr 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through tha...Show more |
3Debian FedoraprojectOpenvpn3Debian Linux FedoraOpenvpnJun 17, 2026 Apr 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data c...Show more |
3Debian FedoraprojectWisc3Debian Linux FedoraHtcondorJun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If...Show more |
3Artifex DebianOpensuse3Debian Linux Jbig2decLeapJun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow. |