Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectMit+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Mar 6, 2018 N/A· v4 3.8 LOW· v3 5.5 MEDIUM· v2 MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument,...Show more |
4Debian FedoraprojectMit+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Mar 6, 2018 N/A· v4 4.7 MEDIUM· v3 6.5 MEDIUM· v2 MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagg...Show more |
3Canonical DebianExempi Project3Debian Linux ExempiUbuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter.cpp, leading to a heap-based buffer over-read in the PSD_MetaHandler::...Show more |
3Canonical DebianExempi Project3Debian Linux ExempiUbuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/...Show more |
2Debian Simplesamlphp3Debian Linux Saml2SimplesamlphpJun 17, 2026 Mar 5, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forc...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickNov 21, 2024 Mar 5, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that...Show more |
2Debian Torproject2Debian Linux TorNov 21, 2024 Mar 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service...Show more |
4Canonical DebianMemcached+1 more4Debian Linux MemcachedOpenstack+1 moreNov 21, 2024 Mar 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via networ...Show more |
3Canonical DebianDovecot3Debian Linux DovecotUbuntu LinuxNov 21, 2024 Mar 2, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart. |
3Debian DovecotUbuntu3Debian Linux DovecotUbuntuNov 21, 2024 Mar 2, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vuln...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Mar 2, 2018 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Mar 1, 2018 N/A· v4 4.7 MEDIUM· v3 5.8 MEDIUM· v2 Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability cou...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Mar 1, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For D...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Mar 1, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain con...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Mar 1, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output d...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Mar 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standa...Show more |
4Canonical DebianQemu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Mar 1, 2018 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which trig...Show more |
5Apache CanonicalDebian+2 more10Debian Linux Fusion MiddlewareHospitality Guest Access+7 moreNov 21, 2024 Feb 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of...Show more |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Feb 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling d...Show more |
2Debian Limesurvey2Debian Linux LimesurveyJun 17, 2026 Feb 28, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file. |