Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OracleVmware33Agile Plm Application Testing SuiteCommunications Diameter Signaling Router+30 moreNov 21, 2024 Jun 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the Hid...Show more |
6Canonical CitrixDebian+3 more14Core I3 Core I5Core I7+11 moreNov 21, 2024 Jun 21, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side ch...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxNov 21, 2024 Jun 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to all...Show more |
2Debian Dovecot2Debian Linux DovecotNov 21, 2024 Jun 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %var...Show more |
2Debian Sam2p Project2Debian Linux Sam2pNov 21, 2024 Jun 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxNov 21, 2024 Jun 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxNov 21, 2024 Jun 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file. |
2Debian Gluster2Debian Linux GlusterfsNov 21, 2024 Jun 20, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privile...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jun 20, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from ps...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraStrongswan+1 moreNov 21, 2024 Jun 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. |
5Canonical DebianFedoraproject+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service. |
2Debian Linaro2Debian Linux LavaNov 21, 2024 Jun 19, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur. |
2Debian Linaro2Debian Linux LavaNov 21, 2024 Jun 19, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is r...Show more |
3Canonical DebianLibjpeg Turbo3Debian Linux Libjpeg TurboUbuntu LinuxNov 21, 2024 Jun 18, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image. |
5Canonical DebianFedoraproject+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service. |
2Debian Phusion2Debian Linux PassengerNov 21, 2024 Jun 17, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is c...Show more |
4Debian OracleRedhat+1 more4Communications Operations Monitor Debian LinuxOpenstack+1 moreNov 21, 2024 Jun 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking. |
4Debian OracleRedhat+1 more4Communications Operations Monitor Debian LinuxOpenstack+1 moreNov 21, 2024 Jun 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows. |
2Debian Discount Project2Debian Linux DiscountNov 21, 2024 Jun 15, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file. |
2Debian Ffmpeg2Debian Linux FfmpegNov 21, 2024 Jun 15, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of...Show more |