Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianFedoraproject+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreJun 17, 2026 Mar 23, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('l...Show more |
2Debian Symfony2Debian Linux TwigJun 17, 2026 Mar 23, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy...Show more |
5Canonical DebianGnu+2 more6Bash Debian LinuxHci Management Node+3 moreJun 17, 2026 Mar 22, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. |
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service...Show more |
8Apple DebianFedoraproject+5 more14Debian Linux Enterprise LinuxEnterprise Linux Desktop+11 moreJun 17, 2026 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execut...Show more |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more |
5Debian FedoraprojectNetapp+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71. |
5Debian FedoraprojectNetapp+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71. |
5Debian FedoraprojectNetapp+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification. |
7Canonical DebianFedoraproject+4 more18Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+15 moreJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. |
7Canonical DebianFedoraproject+4 more15Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+12 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. |
5Canonical DebianOpensuse+2 more5Backports Debian LinuxLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should...Show more |
8Canonical DebianFedoraproject+5 more22Active Iq Performance Analytics Services Debian LinuxEnterprise Linux+19 moreJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An un...Show more |
6Artifex CanonicalDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. |
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be ab...Show more |
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Ser...Show more |
3Canonical DebianLibsndfile Project3Debian Linux LibsndfileUbuntu LinuxJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the app...Show more |
2Debian Yubico2Debian Linux Libu2f HostNov 21, 2024 Mar 21, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device...Show more |
3Debian LinuxNetapp4Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read...Show more |
4Bestpractical CanonicalDebian+1 more4Debian Linux FedoraRequest Tracker+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing. |