Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Bouncycastle DebianNetapp+2 more20Api Gateway Bc JavaBusiness Process Management Suite+17 moreMay 12, 2025 Jun 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have l...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key whe...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA paramet...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and st...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or...Show more |
2Bouncycastle Debian2Bc Java Debian LinuxMay 12, 2025 Jun 4, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on t...Show more |
2Cli Project Debian2Cli Debian LinuxNov 21, 2024 May 31, 2018 N/A· v4 3.5 LOW· v3 4.9 MEDIUM· v2 The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to. |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxJun 17, 2026 May 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. |
2Debian Schedmd2Debian Linux SlurmNov 21, 2024 May 30, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields). |
2Debian Taglib2Debian Linux TaglibNov 21, 2024 May 30, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file. |
5Canonical DebianGit Scm+2 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 May 30, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbit...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxNov 21, 2024 May 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 May 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sens...Show more |
2Debian Discount Project2Debian Linux DiscountNov 21, 2024 May 26, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html. |
2Debian Discount Project2Debian Linux DiscountNov 21, 2024 May 26, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html. |
2Debian Long Range Zip Project2Debian Linux Long Range ZipNov 21, 2024 May 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation. |
4Canonical DebianGiflib Project+1 more4Debian Linux GiflibSam2p+1 moreNov 21, 2024 May 26, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is n...Show more |
2Debian Discount Project2Debian Linux DiscountNov 21, 2024 May 25, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html. |
4Apache CanonicalDebian+1 more21Batik Business IntelligenceCommunications Diameter Signaling Router+18 moreJun 17, 2026 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was t...Show more |