Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Feb 22, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation f...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Feb 22, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub modu...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration p...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a...Show more |
2Debian Wavpack2Debian Linux WavpackJun 17, 2026 Feb 19, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory alloca...Show more |
3Canonical DebianWavpack3Debian Linux Ubuntu LinuxWavpackJun 17, 2026 Feb 19, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted...Show more |
3Debian GoogleXmlsoft3Android Debian LinuxLibxml2Nov 21, 2024 Feb 19, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects. |
3Debian GoogleXmlsoft3Android Debian LinuxLibxml2Dec 3, 2025 Feb 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Dependin...Show more |
4Canonical DebianLibvncserver Project+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Feb 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspe...Show more |
4Canonical DebianQuagga+1 more4Debian Linux QuaggaRuggedcom Rox Ii Firmware+1 moreJun 17, 2026 Feb 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid...Show more |
4Canonical DebianQuagga+1 more4Debian Linux QuaggaRuggedcom Rox Ii Firmware+1 moreJun 17, 2026 Feb 19, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input. |
5Canonical DebianQuagga+2 more9Debian Linux Enterprise Linux ServerEnterprise Linux Server Aus+6 moreJun 17, 2026 Feb 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of s...Show more |
3Canonical DebianQuagga3Debian Linux QuaggaUbuntu LinuxNov 21, 2024 Feb 19, 2018 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the netwo...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Aus+8 moreNov 21, 2024 Feb 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes tha...Show more |
The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execu...Show more |
3Apple CanonicalDebian3Cups Debian LinuxUbuntu LinuxNov 21, 2024 Feb 16, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with...Show more |
2Debian Leptonica2Debian Linux LeptonicaJun 17, 2026 Feb 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspe...Show more |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order. |