Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianGnupg+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 13, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign functi...Show more |
3Debian FedoraprojectRedhat9389 Directory Server Debian LinuxEnterprise Linux+6 moreNov 21, 2024 Jun 13, 2018 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this fla...Show more |
4Canonical DebianQemu+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreNov 21, 2024 Jun 13, 2018 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams. |
2Debian Sensiolabs2Debian Linux SymfonyNov 21, 2024 Jun 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security....Show more |
2Debian Sensiolabs2Debian Linux SymfonyNov 21, 2024 Jun 13, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when t...Show more |
2Debian Sensiolabs2Debian Linux SymfonyNov 21, 2024 Jun 13, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing s...Show more |
3Debian FedoraprojectSensiolabs3Debian Linux FedoraSymfonyNov 21, 2024 Jun 13, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard...Show more |
2Debian Sensiolabs2Debian Linux SymfonyNov 21, 2024 Jun 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of t...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxNov 21, 2024 Jun 13, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp. |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxNov 21, 2024 Jun 13, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp. |
3Debian GoogleRedhat6Android Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Jun 12, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CA...Show more |
2Debian Dinknetwork3Debian Linux DfarcDfarc2Nov 21, 2024 Jun 12, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Jun 12, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a...Show more |
3Debian LinuxRedhat6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Jun 12, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cau...Show more |
2Debian Mruby2Debian Linux MrubyNov 21, 2024 Jun 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c. |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreNov 21, 2024 Jun 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generati...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Jun 12, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specif...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jun 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. |
4Canonical DebianMozilla+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. |
4Canonical DebianMozilla+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 25, 2025 Jun 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbi...Show more |