Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Sep 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker...Show more |
3Canonical DebianTug3Debian Linux Tex LiveUbuntu LinuxNov 21, 2024 Sep 23, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font i...Show more |
2Debian Hylafax2Debian Linux HylafaxNov 21, 2024 Sep 21, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/Copy...Show more |
4Canonical DebianOpenvswitch+1 more4Debian Linux OpenstackOpenvswitch+1 moreNov 21, 2024 Sep 19, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding. |
4Canonical DebianOpenvswitch+1 more4Debian Linux OpenstackOpenvswitch+1 moreNov 21, 2024 Sep 19, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole gro...Show more |
4Artifex CanonicalDebian+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Sep 19, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code. |
4Canonical DebianLinux+1 more5Active Iq Performance Analytics Services Debian LinuxElement Software+2 moreNov 21, 2024 Sep 19, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) v...Show more |
2Debian Matrix2Debian Linux SynapseNov 21, 2024 Sep 18, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation. |
2Debian Smarty2Debian Linux SmartyNov 21, 2024 Sep 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to b...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPython+1 moreNov 21, 2024 Sep 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that c...Show more |
4Apache CanonicalDebian+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Sep 17, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. |
4Apache CanonicalDebian+1 more4Debian Linux PdfinfoSpamassassin+1 moreNov 21, 2024 Sep 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. |
4Apache CanonicalDebian+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+4 moreNov 21, 2024 Sep 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan...Show more |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Sep 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other im...Show more |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Sep 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file. |
3Debian NetappPhp3Debian Linux PhpStorage Automation StoreNov 21, 2024 Sep 16, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in...Show more |
2Debian Opcfoundation5Debian Linux Unified Architecture .net LegacyUnified Architecture Java+2 moreNov 21, 2024 Sep 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Sep 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This...Show more |
2Debian Mgetty Project2Debian Linux MgettyNov 21, 2024 Sep 13, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is possible to use the ||, &&, or > charac...Show more |
2Debian Nothings2Debian Linux Stb Image.hNov 21, 2024 Sep 12, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function. |