Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian RedhatSudo Project4Debian Linux Enterprise LinuxShadow+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into...Show more |
6Broadcom CanonicalDebian+3 more188300 Firmware 8700 FirmwareA400 Firmware+15 moreJun 17, 2026 Nov 4, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the...Show more |
2Berlios Debian2Debian Linux SlimNov 21, 2024 Nov 4, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 slim has NULL pointer dereference when using crypt() method from glibc 2.17 |
3Debian FedoraprojectSmokeping3Debian Linux FedoraSmokepingNov 21, 2024 Nov 1, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. |
3Debian OpenstackRedhat4Compute Debian LinuxKeystone+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates. |
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files. |
2Debian Glpi Project2Debian Linux GlpiNov 21, 2024 Nov 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GLPI 0.83.7 has Local File Inclusion in common.tabs.php. |
4Debian GnomeOpensuse+1 more4Debian Linux Enterprise LinuxEvince+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 evince is missing a check on number of pages which can lead to a segmentation fault |
2Debian Readymedia Project2Debian Linux ReadymediaNov 21, 2024 Nov 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 MiniDLNA has heap-based buffer overflow |
2Debian Miniupnp Project2Debian Linux MiniupnpdNov 21, 2024 Nov 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MiniUPnPd has information disclosure use of snprintf() |
4Debian OpensusePython+1 more7Debian Linux Enterprise LinuxEnterprise Linux Eus+4 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial o...Show more |
2Call Cc Debian2Chicken Debian LinuxNov 21, 2024 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 5.0 MEDIUM· v2 Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack." |
2Call Cc Debian2Chicken Debian LinuxNov 21, 2024 Oct 31, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. |
2Autojump Project Debian2Autojump Debian LinuxNov 21, 2024 Oct 31, 2019 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Oct 31, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. |
2Debian Mantisbt2Debian Linux MantisbtNov 21, 2024 Oct 31, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a comple...Show more |
2Baseurl Debian2Debian Linux YumNov 21, 2024 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. |
2Debian Mumble2Debian Linux MumbleNov 21, 2024 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mumble: murmur-server has DoS due to malformed client query |
2Burn Project Debian2Burn Debian LinuxNov 21, 2024 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 burn allows file names to escape via mishandled quotation marks |
2Debian Python Docutils Project2Debian Linux Python DocutilsNov 21, 2024 Oct 31, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 python-docutils allows insecure usage of temporary files |