Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext. |
2Debian Reproducible Builds2Debian Linux DiffoscopeNov 21, 2024 Apr 13, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. |
2Debian Tuxera2Debian Linux Ntfs 3gDec 4, 2025 Apr 13, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw...Show more |
2Debian Iucode Tool Project2Debian Linux Iucode ToolNov 21, 2024 Apr 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption. |
2Debian Ikiwiki2Debian Linux IkiwikiNov 21, 2024 Apr 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters. |
2Debian Ikiwiki2Debian Linux IkiwikiNov 21, 2024 Apr 13, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Apr 13, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of th...Show more |
4Canonical CorosyncDebian+1 more4Corosync Debian LinuxEnterprise Linux Server+1 moreNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. |
3Clusterlabs DebianRedhat3Debian Linux Enterprise Linux Server EusPacemaker Command Line InterfaceNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensi...Show more |
2Cacti Debian2Cacti Debian LinuxNov 21, 2024 Apr 12, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used). |
2Cacti Debian2Cacti Debian LinuxNov 21, 2024 Apr 12, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php. |
2Debian Ffmpeg2Debian Linux FfmpegNov 21, 2024 Apr 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file. |
3Debian LibsdlStarwindsoftware3Debian Linux Sdl ImageStarwind Virtual SanNov 21, 2024 Apr 10, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, result...Show more |
2Debian Libsdl2Debian Linux Sdl ImageNov 21, 2024 Apr 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting...Show more |
3Debian LibsdlStarwindsoftware3Debian Linux Sdl ImageStarwind Virtual SanNov 21, 2024 Apr 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap,...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input. |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input. |
2Debian Zabbix2Debian Linux ZabbixNov 21, 2024 Apr 9, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbi...Show more |
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file...Show more |
2Debian Roundcube2Debian Linux WebmailJun 17, 2026 Apr 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plug...Show more |