Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianGit Scm+1 more11Ansible Tower Debian LinuxEnterprise Linux+8 moreNov 21, 2024 Oct 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproj...Show more |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Oct 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Oct 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Oct 4, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'. |
6Apache CanonicalDebian+3 more15Communications Application Session Controller Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Oct 4, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially craf...Show more |
4Canonical DebianLinux+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Oct 3, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker...Show more |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxNov 21, 2024 Oct 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. |
2Debian Nullsoft2Debian Linux Nullsoft Scriptable Install SystemNov 21, 2024 Oct 1, 2018 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriat...Show more |
2Debian Nullsoft2Debian Linux Nullsoft Scriptable Install SystemNov 21, 2024 Oct 1, 2018 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be...Show more |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxNov 21, 2024 Sep 28, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of servi...Show more |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Sep 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service. |
2Debian Otrs2Debian Linux Open Ticket Request SystemNov 21, 2024 Sep 28, 2018 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes del...Show more |
2Debian Otrs2Debian Linux Open Ticket Request SystemNov 21, 2024 Sep 28, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the...Show more |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxDec 3, 2025 Sep 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field d...Show more |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxDec 3, 2025 Sep 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PK...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Sep 25, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Sep 25, 2018 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Sep 25, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sendi...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Sep 25, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Sep 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |