Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Jun 26, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Jun 26, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Jun 26, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c. |
4Debian OpensuseOracle+1 more5Database Server Debian LinuxLeap+2 moreJun 17, 2026 Jun 26, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is s...Show more |
2Debian Uclouvain2Debian Linux OpenjpegNov 21, 2024 Jun 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow. |
2Debian Vmware2Debian Linux Spring SecurityJun 17, 2026 Jun 26, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging Plain...Show more |
6Canonical DebianFedoraproject+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreJun 17, 2026 Jun 25, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap abov...Show more |
7Canonical DebianFedoraproject+4 more9Debian Linux FedoraHospitality Res 3700+6 moreMay 30, 2025 Jun 24, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for de...Show more |
3Debian FasterxmlRedhat3Debian Linux Enterprise LinuxJackson DatabindJun 17, 2026 Jun 24, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content,...Show more |
6Bzip CanonicalDebian+3 more6Bzip2 Debian LinuxFreebsd+3 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. |
2Debian Fasterxml2Debian Linux Jackson DatabindJun 17, 2026 Jun 19, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the servi...Show more |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data wh...Show more |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to informa...Show more |
8Canonical DebianFedoraproject+5 more13Debian Linux Enterprise LinuxFedora+10 moreJun 17, 2026 Jun 19, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to...Show more |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsJun 17, 2026 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence inj...Show more |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsJun 17, 2026 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occ...Show more |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsJun 17, 2026 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible. |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsJun 17, 2026 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.) |
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxLeap+1 moreJun 17, 2026 Jun 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eva...Show more |