Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian IscNetapp5Bind Data Ontap EdgeDebian Linux+2 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a re...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when process...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a serv...Show more |
4Debian IscNetapp+1 more10Bind Data Ontap EdgeDebian Linux+7 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL poin...Show more |
6Canonical DebianMariadb+3 more12Debian Linux Enterprise LinuxEnterprise Linux Eus+9 moreJun 17, 2026 Jan 16, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability...Show more |
6Canonical DebianMariadb+3 more15Debian Linux Enterprise LinuxEnterprise Linux Desktop+12 moreJun 17, 2026 Jan 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerab...Show more |
7Canonical DebianHp+4 more18Debian Linux Enterprise LinuxEnterprise Linux Desktop+15 moreJun 17, 2026 Jan 16, 2019 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability a...Show more |
2Debian Uriparser Project2Debian Linux UriparserNov 21, 2024 Jan 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address. |
4Canonical DebianOpensuse+1 more6Ceph Ceph StorageDebian Linux+3 moreNov 21, 2024 Jan 15, 2019 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption. |
4Canonical DebianOpensuse+1 more6Ceph Ceph StorageDebian Linux+3 moreNov 21, 2024 Jan 15, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices. |
4Debian FedoraprojectOpensuse+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 15, 2019 N/A· v4 5.2 MEDIUM· v3 2.7 LOW· v2 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that res...Show more |
2Debian Live5552Debian Linux Live555 Media ServerJun 17, 2026 Jan 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is su...Show more |
2Debian Zeromq2Debian Linux LibzmqJun 17, 2026 Jan 13, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwri...Show more |
3Antigrain DebianSvgpp3Agg Debian LinuxSvgppJun 17, 2026 Jan 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift...Show more |
5Canonical DebianOracle+2 more11Communications Session Border Controller Debian LinuxEnterprise Communications Broker+8 moreNov 21, 2024 Jan 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remo...Show more |
5Canonical DebianOracle+2 more11Communications Session Border Controller Debian LinuxEnterprise Communications Broker+8 moreNov 21, 2024 Jan 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacke...Show more |
5Canonical DebianNetapp+2 more21Active Iq Performance Analytics Services Debian LinuxElement Software+18 moreNov 21, 2024 Jan 11, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 a...Show more |
3Apple CanonicalDebian3Debian Linux Mac Os XUbuntu LinuxNov 21, 2024 Jan 11, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions. |
3Apple CanonicalDebian3Debian Linux Mac Os XUbuntu LinuxNov 21, 2024 Jan 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions. |
4Canonical DebianPolkit Project+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Jan 11, 2019 N/A· v4 6.7 MEDIUM· v3 4.4 MEDIUM· v2 In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in...Show more |