Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianMariadb+2 more9Active Iq Unified Manager Debian LinuxMariadb+6 moreNov 21, 2024 Oct 17, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily explo...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxNov 21, 2024 Oct 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside gu...Show more |
4Canonical DebianMoinmo+1 more4Debian Linux LeapMoinmoin+1 moreNov 21, 2024 Oct 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
3Canonical ClamavDebian3Clamav Debian LinuxUbuntu LinuxNov 21, 2024 Oct 15, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (...Show more |
4Artifex CanonicalDebian+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Oct 15, 2018 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object. |
4Artifex CanonicalDebian+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Oct 15, 2018 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183. |
5Canonical DebianElfutils Project+2 more7Debian Linux ElfutilsEnterprise Linux Desktop+4 moreNov 21, 2024 Oct 15, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a craft...Show more |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Oct 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values. |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Oct 12, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach. |
3Debian OpensuseWireshark3Debian Linux LeapWiresharkNov 21, 2024 Oct 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed. |
3Debian StarwindsoftwareTinc Vpn3Debian Linux Starwind Virtual SanTincNov 21, 2024 Oct 10, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets. |
3Debian StarwindsoftwareTinc Vpn3Debian Linux Starwind Virtual SanTincNov 21, 2024 Oct 10, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1. |
4Canonical DebianQemu+1 more6Debian Linux OpenstackQemu+3 moreNov 21, 2024 Oct 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact. |
6Canonical DebianOracle+3 more6Debian Linux LinuxLinux+3 moreNov 21, 2024 Oct 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used. |
4Canonical DebianQemu+1 more5Debian Linux QemuUbuntu Linux+2 moreApr 28, 2026 Oct 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used. |
2Debian Uclouvain2Debian Linux OpenjpegNov 21, 2024 Oct 9, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c |
5Canonical DebianNet Snmp+2 more10Cloud Backup Data OntapDebian Linux+7 moreNov 21, 2024 Oct 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resultin...Show more |
4Canonical DebianParamiko+1 more11Ansible Tower Debian LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Oct 8, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. |
2Debian Imagemagick2Debian Linux ImagemagickNov 21, 2024 Oct 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 7, 2018 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily re...Show more |