Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraMonit+1 moreJun 17, 2026 Apr 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Au...Show more |
11Backdropcms DebianDrupal+8 more105Agile Product Lifecycle Management For Process Application ExpressApplication Service Level Management+102 moreJun 17, 2026 Apr 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ p...Show more |
4Canonical DebianFfmpeg+1 more4Debian Linux FfmpegSuse Package Hub For Suse Linux Enterprise+1 moreJun 17, 2026 Apr 19, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have...Show more |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Aus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local...Show more |
6Canonical DebianNetapp+3 more6Debian Linux LeapPhp+3 moreJun 17, 2026 Apr 18, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to info...Show more |
6Canonical DebianNetapp+3 more6Debian Linux LeapPhp+3 moreJun 17, 2026 Apr 18, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to in...Show more |
2Debian Redhat2Debian Linux LibvirtNov 21, 2024 Apr 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886. |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacke...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. Th...Show more |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests....Show more |
gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file. |
GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. |
4Canonical DebianLinux+1 more16Codeready Linux Builder Debian LinuxEnterprise Linux+13 moreJun 17, 2026 Apr 11, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. |
4Canonical DebianLinux+1 more16Codeready Linux Builder Debian LinuxEnterprise Linux+13 moreJun 17, 2026 Apr 11, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. |
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled. |
7Canonical DebianFedoraproject+4 more22Active Iq Unified Manager Cloud BackupDebian Linux+19 moreJun 17, 2026 Apr 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XD...Show more |
5Debian FedoraprojectOpensuse+2 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Apr 9, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permission...Show more |