Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Xen2Debian Linux XenNov 21, 2024 Jul 2, 2018 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrator...Show more |
An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reason Xen explicitly checks for the need to preempt the current vCPU at certain points. A few rarely tak...Show more |
2Debian Linuxmint2Cinnamon Debian LinuxNov 21, 2024 Jul 2, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_fac...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Jul 2, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used. |
2Canonical Debian2Devscripts Ubuntu LinuxNov 21, 2024 Jul 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing. |
3Canonical DebianPerl Archive Zip Project3Debian Linux Perl Archive ZipUbuntu LinuxNov 21, 2024 Jun 29, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially craft...Show more |
3Canonical DebianGpac3Debian Linux GpacUbuntu LinuxNov 21, 2024 Jun 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. |
3Canonical DebianGpac3Debian Linux GpacUbuntu LinuxNov 21, 2024 Jun 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Jun 26, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.ph...Show more |
3Debian RedhatSprockets Project4Cloudforms Debian LinuxEnterprise Linux+1 moreNov 21, 2024 Jun 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem t...Show more |
5Debian EclipseHp+2 more19Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+16 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When present...Show more |
2Debian Sympa2Debian Linux SympaNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server file...Show more |
3Debian RedhatRubyzip Project3Cloudforms Debian LinuxRubyzipNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a...Show more |
2Debian Gonicus2Debian Linux GosaNov 21, 2024 Jun 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary...Show more |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxJun 9, 2025 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exp...Show more |
5Debian EclipseHp+2 more17Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+14 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vul...Show more |
2Debian Eclipse2Debian Linux JettyNov 21, 2024 Jun 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space U...Show more |
3Debian FedoraprojectRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jun 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can re...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Jun 26, 2018 N/A· v4 5.3 MEDIUM· v3 6.3 MEDIUM· v2 Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. Th...Show more |
3Debian OracleVmware28Agile Product Lifecycle Management Application Testing SuiteCommunications Network Integrity+25 moreNov 21, 2024 Jun 25, 2018 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpRespons...Show more |