Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Sensiolabs2Debian Linux SymfonyNov 21, 2024 Aug 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded fil...Show more |
2Debian Sensiolabs2Debian Linux SymfonyNov 21, 2024 Aug 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The...Show more |
2Debian Sensiolabs2Debian Linux SymfonyNov 21, 2024 Aug 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS;...Show more |
8A10networks CanonicalCisco+5 more38Advanced Core Operating System Aruba Airwave AmpAruba Clearpass Policy Manager+35 moreJun 17, 2026 Aug 6, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. |
2Debian Otrs2Debian Linux Open Ticket Request SystemNov 21, 2024 Aug 4, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing...Show more |
2Cgit Project Debian2Cgit Debian LinuxNov 21, 2024 Aug 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request. |
3Debian DrupalSensiolabs3Debian Linux DrupalSymfonyNov 21, 2024 Aug 3, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (l...Show more |
3Canonical DebianDjangoproject3Debian Linux DjangoUbuntu LinuxNov 21, 2024 Aug 3, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect. |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Aug 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c. |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Aug 2, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and applica...Show more |
2Apache Debian2Debian Linux TomcatJun 17, 2026 Aug 2, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An...Show more |
4Apache CanonicalDebian+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Aug 2, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5...Show more |
3Apache DebianOracle38Agile Engineering Data Management Agile Product Lifecycle ManagementApplication Testing Suite+35 moreJun 17, 2026 Aug 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. |
4Canonical DebianRedhat+1 more7Ansible Tower Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. |
4Apache CanonicalDebian+1 more4Debian Linux Retail Order BrokerTomcat+1 moreJun 17, 2026 Aug 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.8...Show more |
2Debian Uclouvain2Debian Linux OpenjpegNov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image...Show more |
3Debian Jasper ProjectRedhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected. |
3Debian RedhatUclouvain7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose som...Show more |
3Debian OpenstackRedhat3Debian Linux KeystoneOpenstackNov 21, 2024 Jul 31, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated...Show more |
2Apache Debian2Debian Linux Tomcat NativeJun 17, 2026 Jul 31, 2018 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client cert...Show more |