Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Artifex Debian2Debian Linux MupdfJun 17, 2026 Jan 24, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of servic...Show more |
4Canonical DebianQemu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Jan 23, 2018 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation. |
The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to nega...Show more |
4Canonical DebianGnu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Jan 23, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL. |
3Canonical DebianNlnetlabs3Debian Linux Ubuntu LinuxUnboundNov 21, 2024 Jan 23, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcar...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraLibtasn1Jun 17, 2026 Jan 22, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS. |
4Debian FasterxmlNetapp+1 more9Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+6 moreJun 17, 2026 Jan 22, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploita...Show more |
4Canonical DebianNetapp+1 more12Cloud Backup Clustered Data OntapData Ontap+9 moreApr 29, 2026 Jan 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packe...Show more |