Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian RedhatSamba6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.1 HIGH· v3 4.8 MEDIUM· v2 An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a...Show more |
2Debian Gnome2Debian Linux Network Manager VpncNov 21, 2024 Jul 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration dat...Show more |
2Debian Linux2Debian Linux Linux KernelNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens...Show more |
3Canonical DebianGnupg3Debian Linux LibgcryptUbuntu LinuxNov 21, 2024 Jul 26, 2018 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is...Show more |
4Canonical DebianFreedesktop+1 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jul 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of...Show more |
3Codehaus Plexus DebianRedhat5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Jul 25, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is...Show more |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreNov 21, 2024 Jul 25, 2018 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and...Show more |
3Debian Fuse ProjectRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 24, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option rega...Show more |
2Debian Ffmpeg2Debian Linux FfmpegNov 21, 2024 Jul 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be e...Show more |
2Debian Libconfuse Project2Debian Linux LibconfuseNov 21, 2024 Jul 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read. |
2Debian Uclouvain2Debian Linux OpenjpegNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash). |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Jul 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being c...Show more |
3Canonical DebianXmlsoft3Debian Linux Libxml2Ubuntu LinuxDec 3, 2025 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications process...Show more |
3Canonical DebianRedhat9Ansible Engine Debian LinuxGluster Storage+6 moreNov 21, 2024 Jul 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2...Show more |
2Debian Ffmpeg2Debian Linux FfmpegNov 21, 2024 Jul 19, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format. |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. This was addressed in epan/dissectors/packet-http2.c by verifying that header data was found before proceeding to header...Show more |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by properly handling items that are too l...Show more |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed in...Show more |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths. |
2Debian Wireshark2Debian Linux WiresharkNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow. |