Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache DebianNetapp+2 more16Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+13 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed...Show more |
3Debian FedoraprojectSympa3Debian Linux FedoraSympaJun 17, 2026 Feb 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 24, 2020 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. |
3Canonical DebianFreeradius3Debian Linux Pam RadiusUbuntu LinuxNov 21, 2024 Feb 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted passwo...Show more |
4Apple DebianFedoraproject+1 more8Debian Linux FedoraIpados+5 moreJun 17, 2026 Feb 24, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH...Show more |
2Debian Networkmanager Ssh Project2Debian Linux Networkmanager SshJun 17, 2026 Feb 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled. |
5Cacti DebianFedoraproject+2 more5Cacti Debian LinuxFedora+2 moreJun 17, 2026 Feb 22, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. |
1Debian 2Debian Linux X11 CommonNov 21, 2024 Feb 21, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation. |
2Debian Netsurf Browser2Debian Linux NetsurfNov 21, 2024 Feb 21, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar. |
2Debian Golang2Debian Linux Package SshJun 17, 2026 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also,...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts. |
5Debian FedoraprojectOpensuse+2 more7Backports Sle Debian LinuxFedora+4 moreJun 17, 2026 Feb 20, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution. |
4Debian FedoraprojectOpenidc+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Feb 20, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. |
2Debian Redhat2Ansible Debian LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an i...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacke...Show more |
3Canonical DebianO Dyn3Collabtive Debian LinuxUbuntu LinuxNov 21, 2024 Feb 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3,...Show more |
3Debian FedoraprojectHorde3Debian Linux FedoraGroupwareJun 17, 2026 Feb 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. |
2Debian Linuxfoundation2Debian Linux DojoxJun 17, 2026 Feb 13, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character,...Show more |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 Feb 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malfor...Show more |