Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Rack Project2Debian Linux RackNov 21, 2024 Nov 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited...Show more |
2Debian Nasm2Debian Linux Netwide AssemblerNov 21, 2024 Nov 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Nov 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset. |
2Debian Roundcube2Debian Linux WebmailNov 21, 2024 Nov 12, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment. |
2Debian Uriparser Project2Debian Linux UriparserNov 21, 2024 Nov 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function. |
2Debian Uriparser Project2Debian Linux UriparserNov 21, 2024 Nov 12, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication. |
2Debian Uriparser Project2Debian Linux UriparserNov 21, 2024 Nov 12, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts. |
2Debian Otrs2Debian Linux Open Ticket Request SystemNov 21, 2024 Nov 11, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled. |
2Debian Otrs2Debian Linux Open Ticket Request SystemNov 21, 2024 Nov 11, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled. |
3Debian Jasper ProjectRedhat3Debian Linux FedoraJasperNov 21, 2024 Nov 9, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c. |
2Debian Squid Cache2Debian Linux SquidNov 21, 2024 Nov 9, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet. |
3Debian KeepalivedRedhat7Debian Linux Enterprise Linux ServerEnterprise Linux Server Aus+4 moreNov 21, 2024 Nov 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status cod...Show more |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Nov 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file. |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Nov 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD im...Show more |
4Canonical DebianFreedesktop+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Nov 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.cc lacks a stream check before saving an embedded file. |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker proce...Show more |
4Apple CanonicalDebian+1 more4Debian Linux NginxUbuntu Linux+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default)...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by...Show more |
4Debian LighttpdOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration w...Show more |
2Cached Path Relative Project Debian2Cached Path Relative Debian LinuxNov 21, 2024 Nov 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS a...Show more |