Debian
debian
10,147 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,147)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Apple CanonicalDebian+4 more7Debian Linux LeapMac Os X+4 moreJun 17, 2026 Aug 9, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data wh...Show more |
7Apple CanonicalDebian+4 more7Debian Linux LeapMac Os X+4 moreJun 17, 2026 Aug 9, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data wh...Show more |
4Canonical DebianOpenstack+1 more4Debian Linux NovaOpenstack+1 moreJun 17, 2026 Aug 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the un...Show more |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Aug 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and...Show more |
6Canonical DebianFedoraproject+3 more8Backports Sle Debian LinuxEnterprise Linux Desktop+5 moreJun 17, 2026 Aug 7, 2019 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .dir...Show more |
2Debian Thekelleys2Debian Linux DnsmasqJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability tha...Show more |
3Canonical DebianMilkytracker Project3Debian Linux MilkytrackerUbuntu LinuxJun 17, 2026 Aug 1, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow. |
3Canonical DebianMilkytracker Project3Debian Linux MilkytrackerUbuntu LinuxJun 17, 2026 Aug 1, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow. |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. |
2Debian Opencv2Debian Linux OpencvJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp. |
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter....Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraMilkytracker+1 moreJun 17, 2026 Jul 31, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow. |
3Debian FedoraprojectLibmodbus3Debian Linux FedoraLibmodbusJun 17, 2026 Jul 31, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301. |
3Debian FedoraprojectLibmodbus3Debian Linux FedoraLibmodbusJun 17, 2026 Jul 31, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302. |
3Debian Icedtea Web ProjectOpensuse3Debian Linux Icedtea WebLeapJun 17, 2026 Jul 31, 2019 N/A· v4 8.6 HIGH· v3 6.4 MEDIUM· v2 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This coul...Show more |
3Debian Icedtea Web ProjectOpensuse3Debian Linux Icedtea WebLeapJun 17, 2026 Jul 31, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a tr...Show more |
3Debian FedoraprojectNfdump Project3Debian Linux FedoraNfdumpJun 17, 2026 Jul 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service). |
2Debian Redhat3Ansible Debian LinuxOpenstackJun 17, 2026 Jul 30, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advan...Show more |
2Debian Openmpt2Debian Linux LibopenmptJun 17, 2026 Jul 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files. |
2Debian Libav2Debian Linux LibavJun 17, 2026 Jul 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. |