Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxJun 17, 2026 Apr 3, 2018 N/A· v4 9.1 CRITICAL· v3 7.5 HIGH· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an uninte...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-re...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arb...Show more |
2Debian Ruby Lang2Debian Linux RubyNov 21, 2024 Apr 3, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HT...Show more |
2Debian Eyrie2Debian Linux RemctlNov 21, 2024 Apr 3, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution. |
2Beep Project Debian2Beep Debian LinuxNov 21, 2024 Apr 3, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation. |
5Apple CanonicalDebian+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Apr 3, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is...Show more |
4Apple ChromiumDebian+1 more7Chromium Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Apr 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause...Show more |
6Canonical DebianLinux+3 more12Communications Eagle Application Processor Debian LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Mar 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user. |
2Debian Libming2Debian Linux LibmingJun 17, 2026 Mar 30, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file. |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Mar 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configura...Show more |
2Debian Redhat2Debian Linux LibvirtNov 21, 2024 Mar 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent. |
2Debian Firebirdsql2Debian Linux FirebirdNov 21, 2024 Mar 28, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement. |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Mar 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the con...Show more |
3Canonical DebianOpenssl3Debian Linux OpensslUbuntu LinuxNov 21, 2024 Mar 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There...Show more |
2Debian Loofah Project2Debian Linux LoofahJun 17, 2026 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment. |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerJun 17, 2026 Mar 27, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging lo...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerJun 17, 2026 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=r...Show more |