Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianNetapp5Active Iq Advanced Package ToolDebian Linux+2 moreJun 17, 2026 Jan 28, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machi...Show more |
2Debian Redhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreJun 17, 2026 Jan 28, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to...Show more |
3Canonical DebianLibgd3Debian Linux LibgdUbuntu LinuxJun 17, 2026 Jan 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected. |
5Canonical DebianLibgd+2 more5Debian Linux LibgdPhp+2 moreJun 17, 2026 Jan 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap...Show more |
2Debian Phpmyadmin2Debian Linux PhpmyadminJun 17, 2026 Jan 26, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web serve...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Jan 25, 2019 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("roo...Show more |
3Debian RedhatRsyslog12Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreNov 21, 2024 Jan 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnera...Show more |
2Audiocoding Debian2Debian Linux Freeware Advanced Audio Decoder 2Jun 17, 2026 Jan 25, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c. |
2Debian Mumble2Debian Linux MumbleNov 21, 2024 Jan 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a messag...Show more |
2Debian Postgis2Debian Linux PostgisNov 21, 2024 Jan 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTR...Show more |
3Debian GolangOpensuse3Debian Linux GoLeapJun 17, 2026 Jan 24, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks. |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Jan 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Jan 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous...Show more |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Jan 22, 2019 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal c...Show more |
7Canonical DebianHp+4 more11Bind Data Ontap EdgeDebian Linux+8 moreJun 17, 2026 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers....Show more |
4Canonical DebianIsc+1 more8Debian Linux DhcpEnterprise Linux Desktop+5 moreJun 17, 2026 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4....Show more |
5Debian IscJuniper+2 more10Bind Data Ontap EdgeDebian Linux+7 moreNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8....Show more |
4Canonical DebianIsc+1 more9Debian Linux DhcpEnterprise Linux Desktop+6 moreNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4...Show more |
3Debian IscRedhat8Bind Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an...Show more |
3Debian IscRedhat8Bind Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jan 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructe...Show more |