Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianGoogle3Android Debian LinuxUbuntu LinuxJun 17, 2026 Feb 28, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User in...Show more |
3Debian Live555Opensuse4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Feb 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function. |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Feb 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapUbuntu Linux+1 moreJun 17, 2026 Feb 28, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in ti...Show more |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Feb 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences. |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreJun 17, 2026 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
4Advancemame CanonicalDebian+1 more4Advancecomp Debian LinuxFedora+1 moreJun 17, 2026 Feb 27, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-b...Show more |
3Canonical DebianFreedesktop3Debian Linux PopplerUbuntu LinuxJun 17, 2026 Feb 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to c...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in ba...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when su...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreJun 17, 2026 Feb 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read al...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Feb 21, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures. |
2Debian Libraw2Debian Linux LibrawJun 17, 2026 Feb 20, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources. |
2Debian Libraw2Debian Linux LibrawJun 17, 2026 Feb 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop. |
2Debian Libraw2Debian Linux LibrawJun 17, 2026 Feb 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Feb 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker...Show more |
5Debian OpensuseOracle+2 more9Backports Sle Communications Operations MonitorDebian Linux+6 moreJun 17, 2026 Feb 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Feb 19, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page. |