Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxJun 17, 2026 Oct 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol. |
2Debian Qt2Debian Linux QtbaseJun 17, 2026 Oct 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLoofah+1 moreJun 17, 2026 Oct 22, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. |
5Debian FedoraprojectLibssh2+2 more10Active Iq Unified Manager Bootstrap OsDebian Linux+7 moreJun 17, 2026 Oct 21, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read...Show more |
6Canonical DebianFedoraproject+3 more6Active Iq Unified Manager Debian LinuxFedora+3 moreJun 17, 2026 Oct 21, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). |
3Canonical DebianXmlsoft3Debian Linux LibxsltUbuntu LinuxJun 17, 2026 Oct 18, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and me...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Element Software Management NodeEnterprise Linux+12 moreJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For exa...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow. |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreJun 17, 2026 Oct 16, 2019 N/A· v4 4.7 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attack...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreJun 17, 2026 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulne...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreJun 17, 2026 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulne...Show more |
4Debian NetappOracle+1 more12Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+9 moreJun 17, 2026 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network acc...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreJun 17, 2026 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to ex...Show more |