Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mahara2Debian Linux MaharaNov 21, 2024 Dec 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as use...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+10 moreJun 17, 2026 Dec 17, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the numb...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+10 moreJun 17, 2026 Dec 17, 2019 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is rela...Show more |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Dec 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database. |
3Debian Excon ProjectOpensuse4Backports Sle Debian LinuxExcon+1 moreJul 28, 2026 Dec 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read...Show more |
2Debian Nic2Debian Linux Knot ResolverJun 17, 2026 Dec 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several...Show more |
4Canonical CyrusDebian+1 more4Debian Linux FedoraImap+1 moreJun 17, 2026 Dec 16, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail acc...Show more |
2Debian Requests Kerberos Project2Debian Linux Requests KerberosNov 21, 2024 Dec 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-requests-Kerberos through 0.5 does not handle mutual authentication |
2Debian Imagemagick2Debian Linux ImagemagickNov 21, 2024 Dec 15, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 imagemagick 6.8.9.6 has remote DOS via infinite loop |
2Debian Zend2Debian Linux Zend FrameworkNov 21, 2024 Dec 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ZF2014-03 has a potential cross site scripting vector in multiple view helpers |
3Debian FedoraprojectXfig Project3Debian Linux FedoraFig2devJun 17, 2026 Dec 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. |
2Debian Opensuse3Debian Linux DuplicityOpensuseNov 21, 2024 Dec 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 duplicity 0.6.24 has improper verification of SSL certificates |
3Debian OpensusePen Project3Debian Linux OpensusePenNov 21, 2024 Dec 13, 2019 N/A· v4 4.4 MEDIUM· v3 4.6 MEDIUM· v2 Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities |
3Debian PuppetRedhat3Debian Linux Marionette CollectiveOpenshiftNov 21, 2024 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mcollective has a default password set at install |
2Apache Debian2Debian Linux SpamassassinJun 17, 2026 Dec 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. |
2Apache Debian2Debian Linux SpamassassinNov 21, 2024 Dec 12, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA...Show more |
2Davical Debian2Davical Debian LinuxJun 17, 2026 Dec 12, 2019 N/A· v4 9.3 CRITICAL· v3 4.3 MEDIUM· v2 A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as we...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxLeapJun 17, 2026 Dec 12, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and c...Show more |
3Canonical DebianSysstat Project3Debian Linux SysstatUbuntu LinuxJun 17, 2026 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Dec 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on th...Show more |