Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Pdfresurrect Project2Debian Linux PdfresurrectJun 17, 2026 Mar 2, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document. |
4Debian FasterxmlNetapp+1 more25Active Iq Unified Manager Agile PlmAutovue For Agile Product Lifecycle Management+22 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). |
4Debian FasterxmlNetapp+1 more16Active Iq Unified Manager Autovue For Agile Product Lifecycle ManagementBanking Platform+13 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). |
4Debian FasterxmlNetapp+1 more31Active Iq Unified Manager Agile PlmAutovue For Agile Product Lifecycle Management+28 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). |
4Debian FedoraprojectPuma+1 more4Debian Linux FedoraPuma+1 moreJun 17, 2026 Feb 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inje...Show more |
2Debian W1.fi2Debian Linux HostapdJun 17, 2026 Feb 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fix...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing. |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) ev...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and...Show more |
4Canonical DebianFedoraproject+1 more5Debian Linux Extra Packages For Enterprise LinuxFedora+2 moreJun 17, 2026 Feb 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, the...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpensmtpd+1 moreJun 17, 2026 Feb 25, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to...Show more |
5Canonical DebianLinux+2 more12Active Iq Unified Manager Cloud BackupData Availability Services+9 moreJun 17, 2026 Feb 25, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-...Show more |
7Apache BlackberryDebian+4 more21Agile Engineering Data Management Agile PlmCommunications Element Manager+18 moreJun 17, 2026 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |