Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Dropbear Ssh Project2Debian Linux Dropbear SshNov 21, 2024 Aug 21, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a simil...Show more |
2Canonical Debian2Advanced Package Tool Ubuntu LinuxNov 21, 2024 Aug 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail. |
3Canonical DebianLibgd3Debian Linux LibgdUbuntu LinuxNov 21, 2024 Aug 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigge...Show more |
2Debian Nongnu2Debian Linux ZutilsNov 21, 2024 Aug 20, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim op...Show more |
5Debian Dom4j ProjectNetapp+2 more14Debian Linux Dom4jFlexcube Investor Servicing+11 moreNov 21, 2024 Aug 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection....Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Aug 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Aug 20, 2018 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which makes it easier for attackers to conduct userspace-userspace...Show more |
2Debian Libgit22Debian Linux Libgit2Nov 21, 2024 Aug 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to...Show more |
2Debian Dojotoolkit2Debian Linux DojoNov 21, 2024 Aug 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. |
7Canonical DebianNetapp+4 more22Aff Baseboard Management Controller Cloud BackupClustered Data Ontap+19 moreDec 17, 2025 Aug 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c,...Show more |
An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be p...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Aug 17, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send speci...Show more |
3Canonical DebianXmlsoft3Debian Linux Libxml2Ubuntu LinuxNov 21, 2024 Aug 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability...Show more |
3Debian FedoraprojectLibcgroup Project3Debian Linux FedoraLibcgroupNov 21, 2024 Aug 14, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information. |
3Canonical CupsDebian3Cups Debian LinuxUbuntu LinuxJun 17, 2026 Aug 10, 2018 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubu...Show more |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxNov 21, 2024 Aug 9, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "...Show more |
4Canonical DebianPostgresql+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 9, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" co...Show more |
3Canonical DebianW1.fi3Debian Linux Ubuntu LinuxWpa SupplicantNov 21, 2024 Aug 8, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the A...Show more |
2Debian Libtiff2Debian Linux LibtiffNov 21, 2024 Aug 8, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a craf...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Aug 7, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call. |